There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.@smb[%d].username in the apply.cgi interface, thereby gaining root shell privileges.
The vulnerability is located in the router's apply.cgi interface and consists of insufficient input data validation in POST request parameters — specifically in the 'usapps.@smb[%d].username' parameter. An attacker can inject arbitrary system commands through a specially crafted HTTP POST request. Since the attack requires no authentication or user interaction, and the attack vector is network-based, the vulnerability is particularly dangerous for devices accessible from the Internet.
An attacker gains an interactive system shell session (root shell) on the device, which means full takeover of the router — ability to modify network configuration, intercept traffic, install malware, and use the device as a launching point for further attacks on the internal network.
Patches available from the manufacturer should be applied according to references. Until an update is applied, it is recommended to restrict access to the router's management interface only to trusted hosts on the local network and block access to the admin panel from the WAN side.
TRENDnet TEW-827DRU router with firmware version 2.10B01
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HTrendnet Tew 827dru
HWTrendnetall versionsTrendnet Tew 827dru Firmware
OSTrendnet2.10b01
Related vulnerabilities
Authentication Bypass w Trendnet TEW-827DRU — wymuszenie zmiany hasła admina
Hardcoded credentials w Trendnet TEW-827DRU — szyfrowanie konfiguracji
Trendnet TEW-827DRU: przejęcie sesji przez weryfikację IP zamiast tokenów
TRENDnet TEW-827DRU — brak kontroli dostępu przez IPv6 na interfejsie WAN
Stack-based buffer overflow w TRENDnet TEW-827DRU — nieuwierzytelniony RCE