Command Injection Vulnerability in TRENDnet TEW-827DRU Router
CVE-2024-28354
10CRITICAL
What is CVE-2024-28354?
A command injection vulnerability exists in the TRENDnet TEW-827DRU router, specifically within the apply.cgi interface. By exploiting this vulnerability, attackers can inject malicious commands into the post request parameters, particularly targeting usapps.@smb[%d].username. Successful exploitation allows unauthorized users to gain root shell privileges, potentially compromising the device and connected network resources.
