CVE-2025-2957 | TRENDnet TEW-411BRP+ 2.07 HTTP Request /usr/sbin/httpd sub_401DB0 null pointer dereference
A vulnerability was found in TRENDnet TEW-411BRP+ 2.07. It has been classified as problematic. Affected is the function sub_401DB0 of the file /usr/sbin/httpd of the component HTTP Request Handler. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2025-2957. The attack can only be initiated within the local network. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
The vendor was contacted early about this disclosure but did not respond in any way.