CVE-2021-20163

MEDIUM

Trendnet Tew-827dru Firmware - Insufficiently Protected Credentials

Title source: rule

Description

Trendnet AC2600 TEW-827DRU version 2.08B01 leaks information via the ftp web page. Usernames and passwords for all ftp users are revealed in plaintext on the ftpserver.asp page.

Scores

CVSS v3 4.9
EPSS 0.0026
EPSS Percentile 49.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-522
Status published

Affected Products (1)

trendnet/tew-827dru_firmware

Timeline

Published Dec 30, 2021
Tracked Since Feb 18, 2026