Information Disclosure in Trendnet AC2600 TEW-827DRU Due to FTP Web Page Misconfiguration
CVE-2021-20163
4.9MEDIUM
What is CVE-2021-20163?
The Trendnet AC2600 TEW-827DRU version 2.08B01 has a significant vulnerability whereby sensitive user credentials are leaked through the FTP web page. When accessing the ftpserver.asp page, all usernames and passwords for FTP users are displayed in plaintext, allowing unauthorized individuals to access confidential data and potentially compromise network security.
Affected Version(s)
Trendnet AC2600 TEW-827DRU 2.08B01
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved