Record summary

CVE-2021-20158 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicous actor to force the change of the admin password due to a hidden administrative command.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Trendnet AC2600 TEW-827DRU

CVE List2.08B01affected

Nuclei templates

1
ProjectDiscoveryCRITICALTrendnet AC2600 TEW-827DRU 2.08B01 - Admin Password ChangeCVSS 9.8

Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicious actor to force change the admin password due to a hidden administrative command.

Impact

An attacker with authenticated access can gain unauthorized control over the affected device.

Remediation

Upgrade to the latest firmware version provided by Trendnet to fix the vulnerability.

WeaknessesCWE-306
Authorsgy741
Template tagscve2021cvedisclosurerouterintrusivetenabletrendnetvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:trendnet:tew-827dru_firmware:2.08b01:*:*:*:*:*:*:*
Shodan: http.html:"TEW-827DRU"
Shodan: http.html:"tew-827dru"
FOFA: body="tew-827dru"

Source: ProjectDiscovery

References

2