Record summary

CVE-2021-20150 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authentication can be bypassed and a user may view information as Admin by manually browsing to the setup wizard and forcing it to redirect to the desired page.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Trendnet AC2600 TEW-827DRU

CVE List2.08B01affected

Nuclei templates

1
ProjectDiscoveryMEDIUMTrendnet AC2600 TEW-827DRU - Credentials DisclosureCVSS 5.3

Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. A user may view information as Admin by manually browsing to the setup wizard and forcing it to redirect to the desired page.

Impact

An attacker can obtain sensitive credentials, leading to unauthorized access to the router.

Remediation

Update the router firmware to the latest version to fix the vulnerability.

WeaknessesCWE-306
Authorsgy741
Template tagscve2021cvedisclosureroutertenabletrendnetvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:o:trendnet:tew-827dru_firmware:2.08b01:*:*:*:*:*:*:*
Shodan: http.html:"TEW-827DRU"
Shodan: http.html:"tew-827dru"
FOFA: body="tew-827dru"

Source: ProjectDiscovery

References

2