CVE-2021-20164
MEDIUMTrendnet Tew-827dru Firmware - Insufficiently Protected Credentials
Title source: ruleDescription
Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses credentials for the smb functionality of the device. Usernames and passwords for all smb users are revealed in plaintext on the smbserver.asp page.
Scores
CVSS v3
4.9
EPSS
0.0026
EPSS Percentile
49.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-522
Status
published
Affected Products (1)
trendnet/tew-827dru_firmware
Timeline
Published
Dec 30, 2021
Tracked Since
Feb 18, 2026