CVE-2025-8759 Details
Description
A vulnerability was found in TRENDnet TN-200 1.02b02. It has been declared as problematic. This vulnerability affects unknown code of the component Lighttpd. The manipulation of the argument secdownload.secret with the input neV3rUseMe leads to use of hard-coded cryptographic key . The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability exists in the TRENDnet TN-200 NAS device running version 1.02b02, related to the Lighttpd component. The issue arises from the secdownload.secret argument, which can be manipulated to use a hard-coded cryptographic key. This vulnerability allows remote attackers to forge secure download links, gaining unauthorized access to protected files on the NAS. The exploitation of this vulnerability is considered difficult, but a public exploit is available.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/?ctiid.319264 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.319264 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.624555 | [email protected] | Third Party AdvisoryVDB Entry |
| https://www.notion.so/23f54a1113e7801e944ec65a2f7c5448 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-320 | Key Management Errors | [email protected] |
| CWE-321 | Use of Hard-coded Cryptographic Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| trendnet tn-200 firmware | 1.02b02 |
CPE
Remediation
| |
| trendnet tn-200 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Jan 2, 2026 | Modified Analysis | [email protected] |
| Oct 6, 2025 | Initial Analysis | [email protected] |
| Aug 9, 2025 | New CVE Received | [email protected] |