We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-2956

TRENDnet TI-G102i HTTP Request lighttpd plugins_call_handle_uri_raw null pointer dereference



Description

EN DE

A vulnerability was found in TRENDnet TI-G102i 1.0.7.S0_ /1.0.8.S0_ and classified as problematic. This issue affects the function plugins_call_handle_uri_raw of the file /usr/sbin/lighttpd of the component HTTP Request Handler. The manipulation leads to null pointer dereference. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Eine problematische Schwachstelle wurde in TRENDnet TI-G102i 1.0.7.S0_ /1.0.8.S0_ gefunden. Hierbei geht es um die Funktion plugins_call_handle_uri_raw der Datei /usr/sbin/lighttpd der Komponente HTTP Request Handler. Durch Manipulation mit unbekannten Daten kann eine null pointer dereference-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff im lokalen Netzwerk. Der Exploit steht zur öffentlichen Verfügung.

Reserved 2025-03-29 | Published 2025-03-30 | Updated 2025-03-31 | Assigner VulDB


HIGH: 7.1CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
MEDIUM: 6.5CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
MEDIUM: 6.5CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
6.1AV:A/AC:L/Au:N/C:N/I:N/A:C

Problem types

NULL Pointer Dereference

Denial of Service

Product status

1.0.7.S0_
affected

1.0.8.S0_
affected

Timeline

2025-03-29:Advisory disclosed
2025-03-29:VulDB entry created
2025-03-29:VulDB entry last update

Credits

zhongwei gu (VulDB User) reporter

References

vuldb.com/?id.302009 (VDB-302009 | TRENDnet TI-G102i HTTP Request lighttpd plugins_call_handle_uri_raw null pointer dereference) vdb-entry technical-description

vuldb.com/?ctiid.302009 (VDB-302009 | CTI Indicators (IOB, IOC, IOA)) signature permissions-required

vuldb.com/?submit.521717 (Submit #521717 | TRENDnet Router FW_TI_G102i_v1_1.0.8.S0_/FW_TI_G642i_v1_1.0.7.S0_ NULL Pointer Dereference) third-party-advisory

docs.google.com/.../d/16iWGXHpmlwJ0GAOi458YlpR56McCvDcN/edit related

drive.google.com/...Jbh1PdPbk0PRwJB8-fc5mYR/view?usp=sharing exploit

cve.org (CVE-2025-2956)

nvd.nist.gov (CVE-2025-2956)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-2956

Support options

Helpdesk Chat, Email, Knowledgebase