CVE-2021-28846 is a Format String vulnerability affecting specific TRENDnet TEW-755AP, TEW-755AP2KAC, TEW-821DAP2KAC, and TEW-825DAP firmware versions. A remote, authenticated attacker can trigger a denial of service by sending a crafted POST request to the apply_cgi endpoint with a malformed key. This vulnerability has a CVSS score of 6.5 (Medium) due to its network attack vector and low attack complexity, leading to high availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.11b03CPE matchmatch criteria | cpe:2.3:o:trendnet:tew-755ap_firmware:1.11b03:*:*:*:*:*:*:* | ||
1.11b03CPE matchmatch criteria | cpe:2.3:o:trendnet:tew-755ap2kac_firmware:1.11b03:*:*:*:*:*:*:* | ||
1.11b03CPE matchmatch criteria | cpe:2.3:o:trendnet:tew-821dap2kac_firmware:1.11b03:*:*:*:*:*:*:* | ||
1.11b03CPE matchmatch criteria | cpe:2.3:o:trendnet:tew-825dap_firmware:1.11b03:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.