CVE-2021-32459

MEDIUM

Trend Micro Home Network Security < 6.6.604 - Use of Hard-coded Credentials in Log Collection Server

Title source: llm
STIX 2.1

Description

Trend Micro Home Network Security version 6.6.604 and earlier contains a hard-coded password vulnerability in the log collection server which could allow an attacker to use a specially crafted network request to lead to arbitrary authentication. An attacker must first obtain the ability to execute high-privileged code on the target device in order to exploit this vulnerability.

References (2)

Core 2
Core References

Scores

CVSS v3 6.5
EPSS 0.0053
EPSS Percentile 67.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-798
Status published
Products (1)
trendmicro/home_network_security < 6.6.604 (3 CPE variants)
Published May 27, 2021
Tracked Since Feb 18, 2026