|
197981
|
6.8 |
MEDIUM
Physics
|
trendnet
|
tew-827dru_firmware
|
Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient protections for the UART functionality. A malicious actor with physical access to the device is able to connect to the UART port vi…
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2021-20161
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197982
|
8.8 |
HIGH
Network
|
trendnet
|
tew-827dru_firmware
|
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a command injection vulnerability in the smb functionality of the device. The username parameter used when configuring smb functionality for the de…
|
CWE-78
OS Command
|
CVE-2021-20160
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197983
|
8.8 |
HIGH
Network
|
trendnet
|
tew-827dru_firmware
|
Trendnet AC2600 TEW-827DRU version 2.08B01 is vulnerable to command injection. The system log functionality of the firmware allows for command injection as root by supplying a malformed parameter.
|
CWE-78
OS Command
|
CVE-2021-20159
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197984
|
9.8 |
CRITICAL
Network
|
trendnet
|
tew-827dru_firmware
|
Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicous actor to force the change of the admin password due to a hi…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-20158
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197985
|
7.5 |
HIGH
Network
|
trendnet
|
tew-827dru_firmware
|
It is possible for an unauthenticated, malicious user to force the device to reboot due to a hidden administrative command.
|
NVD-CWE-noinfo
|
CVE-2021-20157
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197986
|
6.5 |
MEDIUM
Network
|
trendnet
|
tew-827dru_firmware
|
Trendnet AC2600 TEW-827DRU version 2.08B01 contains an improper access control configuration that could allow for a malicious firmware update. It is possible to manually install firmware that may be …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2021-20156
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197987
|
9.8 |
CRITICAL
Network
|
trendnet
|
tew-827dru_firmware
|
Trendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore device configurations via the management web interface. These devices are encrypted…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-20155
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197988
|
7.5 |
HIGH
Network
|
trendnet
|
tew-827dru_firmware
|
Trendnet AC2600 TEW-827DRU version 2.08B01 contains an security flaw in the web interface. HTTPS is not enabled on the device by default. This results in cleartext transmission of sensitive informati…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2021-20154
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197989
|
6.8 |
MEDIUM
Physics
|
trendnet
|
tew-827dru_firmware
|
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a symlink vulnerability in the bittorrent functionality. If enabled, the bittorrent functionality is vulnerable to a symlink attack that could lead…
|
CWE-59
Link Following
|
CVE-2021-20153
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197990
|
6.5 |
MEDIUM
Network
|
trendnet
|
tew-827dru_firmware
|
Trendnet AC2600 TEW-827DRU version 2.08B01 lacks proper authentication to the bittorrent functionality. If enabled, anyone is able to visit and modify settings and files via the Bittorent web client …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-20152
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|