Junglewise Threat Intelligence

CVE-2025-44651: TRENDnet TPL-430AP denial of service in bftpd configuration

CVE-2025-44651 · Severity: high · CVSS 7.5 · Published 2025-07-21

Vendors: TRENDnet.

Executive brief

A vulnerability exists in the TRENDnet TPL-430AP wireless access point that could allow an attacker to crash the device or make it unavailable. The issue is caused by a configuration error that fails to limit the number of simultaneous users allowed to connect to the device's file transfer service. If exploited, this could lead to a total service outage, preventing legitimate users from accessing the network or its features.

Technical details

The TRENDnet TPL-430AP access point (firmware version 1.0) contains a resource exhaustion vulnerability (CWE-400) within its bftpd configuration. The 'USERLIMIT_GLOBAL' parameter is incorrectly set to 0, which the service interprets as allowing an unlimited number of concurrent connections. A remote, unauthenticated attacker can exploit this by initiating a large number of connections to the FTP service, exhausting system resources and causing a denial-of-service (DoS) state. This is a network-based attack requiring no user interaction.

Affected products

  • TRENDnet TPL-430AP Firmware 1.0

Timeline

  • 2025-07-21: disclosed
  • 2025-07-21: advisory

References