Discoverer


Team StellarFlare (Jeongwon Seok, Yeeun Lee, Haim Lee, Munju Lim, Minu Cho, Gyeongmin Hong)

Description


Trendnet TEW-929DRU devices contain a Stored Cross-site Scripting (XSS) vulnerability via the r_name variable inside the have_same_name function on the /addschedule.htm page.

Overview


Vulnerability Information


스크린샷 2025-01-11 오후 4.31.42.png

In the settings under the "System" page, there is an option called "Schedule". This setting is used to manage schedule rules