CVE-2025-2957
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Mar 30, 2025
Updated: Apr 1, 2025
CWE ID 276
Summary
CVE-2025-2957 is a recently disclosed vulnerability affecting the TRENDnet TEW-411BRP+ 2.07. This issue is classified as problematic and lies within the HTTP Request Handler component, specifically in the sub_401DB0 function of the /usr/sbin/httpd file. The weakness results in a null pointer dereference, which can be exploited by attackers present in the local network. The exploit code has been made public, increasing the risk of potential attacks. Despite early contact from security researchers, the vendor has not responded to address this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.