CVE-2025-44651

In TRENDnet TPL-430AP FW1.0, the USERLIMIT_GLOBAL option is set to 0 in the bftpd-related configuration file. This can cause DoS attacks when unlimited users are connected.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:trendnet:tpl-430ap_firmware:1.0:*:*:*:*:*:*:*
cpe:2.3:h:trendnet:tpl-430ap:-:*:*:*:*:*:*:*

History

07 Aug 2025, 17:56

Type Values Removed Values Added
First Time Trendnet tpl-430ap Firmware
Trendnet
Trendnet tpl-430ap
CPE cpe:2.3:o:trendnet:tpl-430ap_firmware:1.0:*:*:*:*:*:*:*
cpe:2.3:h:trendnet:tpl-430ap:-:*:*:*:*:*:*:*
References () http://trendnet.com - () http://trendnet.com - Product
References () https://gist.github.com/TPCchecker/9e27534ec59babcd4fd44d18fe7a56b3 - () https://gist.github.com/TPCchecker/9e27534ec59babcd4fd44d18fe7a56b3 - Broken Link
References () https://www.notion.so/CVE-2025-44651-24754a1113e780da990eec3961100ae0 - () https://www.notion.so/CVE-2025-44651-24754a1113e780da990eec3961100ae0 - Third Party Advisory

07 Aug 2025, 14:15

Type Values Removed Values Added
Summary
  • (es) En TRENDnet TPL-430AP FW1.0, la opción USERLIMIT_GLOBAL está establecida en 0 en el archivo de configuración relacionado con bftpd. Esto puede provocar ataques DoS cuando se conectan usuarios ilimitados.
References
  • () https://www.notion.so/CVE-2025-44651-24754a1113e780da990eec3961100ae0 -

22 Jul 2025, 16:15

Type Values Removed Values Added
CWE CWE-400
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

21 Jul 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-21 16:15

Updated : 2025-08-07 17:56


NVD link : CVE-2025-44651

Mitre link : CVE-2025-44651

CVE.ORG link : CVE-2025-44651


JSON object : View

Products Affected

trendnet

  • tpl-430ap
  • tpl-430ap_firmware
CWE
CWE-400

Uncontrolled Resource Consumption