An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the wps_sta_enrollee_pin parameter in a set_sta_enrollee_pin.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected.
| Software | From | Fixed in |
|---|---|---|
| dlink / dir-825_firmware | 2.10 | 2.10.x |
| trendnet / tew-632brp_firmware | 1.010b32 | 1.010b32.x |