Remote Access Vulnerability in Trendnet AC2600 Router Devices
CVE-2021-20161

6.8MEDIUM

Key Information:

Vendor

Trendnet

Vendor
CVE Published:
30 December 2021

What is CVE-2021-20161?

The Trendnet AC2600 TEW-827DRU router versions, particularly 2.08B01, are susceptible to a security flaw that allows unauthorized physical access through the UART port. Attackers with physical access can exploit this vulnerability by connecting a serial device to the UART interface. This connection does not require authentication, granting them a root shell and full control over the router. Such an exploit can lead to unauthorized activities, including configuration changes and network manipulation.

Affected Version(s)

Trendnet AC2600 TEW-827DRU 2.08B01

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.