CVE-2021-20150
Trendnet AC2600 TEW-827DRU - Credentials Disclosure
Record summary
CVE-2021-20150 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authentication can be bypassed and a user may view information as Admin by manually browsing to the setup wizard and forcing it to redirect to the desired page.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Trendnet AC2600 TEW-827DRU | CVE List | 2.08B01 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMTrendnet AC2600 TEW-827DRU - Credentials DisclosureCVSS 5.3
Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. A user may view information as Admin by manually browsing to the setup wizard and forcing it to redirect to the desired page.
Impact
An attacker can obtain sensitive credentials, leading to unauthorized access to the router.
Remediation
Update the router firmware to the latest version to fix the vulnerability.
Source: ProjectDiscovery