CVE-2024-46484

Executive Summary

TRENDnet TV-IP410 vA1.0R is vulnerable to OS command injection via the /server/cgi-bin/testserv.cgi endpoint, allowing attackers to execute arbitrary shell commands on the device. This flaw can lead to full device compromise, enabling data exfiltration, malware installation, or network disruption. The vulnerability is not yet listed in CISA KEV but requires immediate mitigation.


Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2025-08-29T20:15:34.473 - Last Modified: 2026-10-06T22:10:00.247

Original Description: TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testserv.cgi component.

"I have always thought the actions of men the best interpreters of their thoughts."

— John Locke
Source: NVD