Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient access controls for the WAN interface. The default iptables ruleset for governing access to services on the device only apply to IPv4. All services running on the devices are accessible via the WAN interface via IPv6 by default.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HTrendnet Tew 827dru
HWTrendnet2.0Trendnet Tew 827dru Firmware
OSTrendnet2.08b01
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2024-28354CRITICAL10.0PL ✓same product
Command injection w routerze TRENDnet TEW-827DRU — zdalny dostęp root
CVE-2021-20158CRITICAL9.8PL ✓same product
Authentication Bypass w Trendnet TEW-827DRU — wymuszenie zmiany hasła admina
CVE-2021-20155CRITICAL9.8PL ✓same product
Hardcoded credentials w Trendnet TEW-827DRU — szyfrowanie konfiguracji
CVE-2021-20151CRITICAL10.0PL ✓same product
Trendnet TEW-827DRU: przejęcie sesji przez weryfikację IP zamiast tokenów
CVE-2020-14080CRITICAL9.8PL ✓same product
Stack-based buffer overflow w TRENDnet TEW-827DRU — nieuwierzytelniony RCE