CVE-2019-13155

HIGH

TRENDnet TEW-827DRU Firmware < 2.05b11 - Authenticated OS Command Injection via Add Virtual Server IP Address

Title source: llm
STIX 2.1

Description

An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) via the IP Address in Add Virtual Server.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0752
EPSS Percentile 91.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
trendnet/tew-827dru_firmware < 2.05b11
Published Jul 02, 2019
Tracked Since Feb 18, 2026