Information Disclosure Vulnerability in Trendnet AC2600 TEW-827DRU Router
CVE-2021-20150

5.3MEDIUM

Key Information:

Vendor

Trendnet

Vendor
CVE Published:
30 December 2021

What is CVE-2021-20150?

The Trendnet AC2600 TEW-827DRU router has a flaw in its setup wizard that allows unauthorized users to gain access to sensitive administrative information. By bypassing authentication through a specific redirect, attackers can view information that should only be available to authenticated administrators. This vulnerability poses a significant risk, as it allows potential intruders to exploit the router's configuration and access critical data.

Affected Version(s)

Trendnet AC2600 TEW-827DRU 2.08B01

References

EPSS Score

38% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.