CVE-2021-20158
Trendnet AC2600 TEW-827DRU 2.08B01 - Admin Password Change
Record summary
CVE-2021-20158 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicous actor to force the change of the admin password due to a hidden administrative command.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Trendnet AC2600 TEW-827DRU | CVE List | 2.08B01 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALTrendnet AC2600 TEW-827DRU 2.08B01 - Admin Password ChangeCVSS 9.8
Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicious actor to force change the admin password due to a hidden administrative command.
Impact
An attacker with authenticated access can gain unauthorized control over the affected device.
Remediation
Upgrade to the latest firmware version provided by Trendnet to fix the vulnerability.
Source: ProjectDiscovery