Command Injection Vulnerability in TRENDnet Routers
CVE-2019-13278
9.8CRITICAL
What is CVE-2019-13278?
The TRENDnet TEW-827DRU router with firmware versions up to and including 2.04B03 is susceptible to command injection vulnerabilities within its setup wizard. An attacker can exploit these vulnerabilities via user input processing, enabling unauthorized execution of arbitrary commands on the device. This could occur from the local intranet or from remote locations if remote administration features are enabled. Proper measures should be taken to secure vulnerable devices and ensure that only trusted users have access.
References
EPSS Score
60% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved