Information Disclosure Vulnerability in Trendnet AC2600 TEW-827DRU Router
CVE-2021-20150
5.3MEDIUM
What is CVE-2021-20150?
The Trendnet AC2600 TEW-827DRU router has a flaw in its setup wizard that allows unauthorized users to gain access to sensitive administrative information. By bypassing authentication through a specific redirect, attackers can view information that should only be available to authenticated administrators. This vulnerability poses a significant risk, as it allows potential intruders to exploit the router's configuration and access critical data.
Affected Version(s)
Trendnet AC2600 TEW-827DRU 2.08B01
References
EPSS Score
38% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved