Format String Vulnerability in TRENDnet Wireless Access Points
CVE-2021-28846

6.5MEDIUM

Key Information:

Vendor

Trendnet

Vendor
CVE Published:
10 August 2021

What is CVE-2021-28846?

A Format String vulnerability in specific TRENDnet wireless access points could allow a remote attacker to trigger a denial of service. This issue arises due to incorrect ordering of variables in the fprintf function, leading to potential lapses in application logic when processing POST requests containing excessively long keys. By exploiting this vulnerability, attackers may interrupt the service, impacting the availability of the affected devices.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.