CVE-2021-20153
MEDIUMTrendnet AC2600 TEW-827DRU 2.08B01 - Remote Code Execution via BitTorrent Symlink Attack
Title source: llmDescription
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a symlink vulnerability in the bittorrent functionality. If enabled, the bittorrent functionality is vulnerable to a symlink attack that could lead to remote code execution on the device. If an end user inserts a flash drive with a malicious symlink on it that the bittorrent client can write downloads to, then a user is able to download arbitrary files to any desired location on the devices filesystem, which could lead to remote code execution. Example directories vulnerable to this include "config", "downloads", and "torrents", though it should be noted that "downloads" is the only vector that allows for arbitrary files to be downloaded to arbitrary locations.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.tenable.com/security/research/tra-2021-54
Scores
CVSS v3
6.8
EPSS
0.0030
EPSS Percentile
53.7%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-59
Status
published
Products (1)
trendnet/tew-827dru_firmware
2.08b01
Published
Dec 30, 2021
Tracked Since
Feb 18, 2026