Setup Wizard Bypass in TRENDnet Router
CVE-2019-13277

7.5HIGH

Key Information:

Vendor

Trendnet

Vendor
CVE Published:
9 July 2019

What is CVE-2019-13277?

The TRENDnet TEW-827DRU firmware version 2.04B03 and earlier is susceptible to a security vulnerability that allows unauthenticated users to leverage the setup wizard functionality. This can grant an attacker the ability to modify crucial configuration settings, potentially causing service disruptions and denial of service. If remote administration is enabled, these malicious requests can be executed from outside the local network, heightening the risk of unauthorized access and control.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.