CVE-2021-20155 describes a critical vulnerability in Trendnet AC2600 TEW-827DRU version 2.08B01, involving hardcoded credentials used to encrypt device configuration backups. This allows an unauthenticated attacker to remotely access, modify, and restore device configurations, leading to full compromise. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with low attack complexity, posing a high risk to confidentiality, integrity, and availability. While no public exploit code is officially available, the vulnerability has garnered significant community discussion, indicating potential interest in developing exploits, though it is not currently listed as actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.08b01CPE matchmatch criteria | cpe:2.3:o:trendnet:tew-827dru_firmware:2.08b01:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Trendnet AC2600 TEW-827DRU Multiple Vulnerabilities
Dec 30, 2021Trendnet AC2600 TEW-827DRU Multiple Vulnerabilities
Dec 30, 2021Trendnet AC2600 TEW-827DRU Multiple Vulnerabilities
Dec 30, 2021