Command Injection Vulnerability in TRENDnet TEW-827DRU Firmware
CVE-2019-13150
8.8HIGH
What is CVE-2019-13150?
A command injection vulnerability has been identified in the TRENDnet TEW-827DRU firmware versions prior to 2.05B11. This flaw occurs within the 'apply.cgi' file and can be exploited via authenticated access, where maliciously crafted input to the 'ip_addr' key can allow an attacker to execute arbitrary commands on the device. Users are advised to update their firmware to mitigate this risk.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved