Stack-based Buffer Overflow in TRENDnet TEW-827DRU Devices
CVE-2024-36728
What is CVE-2024-36728?
The TRENDnet TEW-827DRU devices, specifically versions up to and including 2.06B04, are susceptible to a stack-based buffer overflow that occurs within the 'ssi' binary. This vulnerability allows an authenticated user to exploit the system by sending specially crafted POST requests to the 'apply.cgi' endpoint, particularly through the 'action vlan_setting' parameter. By excessively lengthening the inputs for the 'dns1' or 'dns2' keys, an attacker can execute arbitrary code on the device. Such vulnerabilities pose significant risks to network integrity and confidentiality, warranting immediate attention and remediation to secure affected devices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
