Executive brief
A security vulnerability has been identified in the TRENDnet TV-IP410 network camera. This flaw allows an unauthorized person to take complete control of the device over the internet. An attacker could use this access to monitor video feeds, disable the camera, or use the device as a foothold to attack other systems on your internal network.
Technical details
An OS command injection vulnerability (CWE-78) exists in the TRENDnet TV-IP410 network camera running firmware version A1.0R. The flaw is located within the /server/cgi-bin/testserv.cgi component, which fails to properly neutralize special elements in user-supplied input. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to the vulnerable CGI script. Successful exploitation allows for arbitrary command execution with the privileges of the web server, potentially leading to full system compromise. No user interaction is required for exploitation.
Affected products
- TRENDnet TV-IP410 firmware A1.0R
Timeline
- 2025-08-29: disclosed
- 2025-08-29: advisory