CVE-2019-13154: OS Command Injection
Published Jul 2, 2019
·Updated
An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) via the TCP Ports To Open in Add Gaming Rule.
Affected Software
2 affected components
Trendnet TEW-827DRU firmware<2.05b11
Trendnet TEW-827DRU
Event History
Jul 2, 2019
CVE Published
via MITRE·12:17 PM
Data Sourced
via MITRE·12:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13154?
CVE-2019-13154 has a medium severity rating due to its command injection vulnerability.
2
How do I fix CVE-2019-13154?
To fix CVE-2019-13154, upgrade to TRENDnet TEW-827DRU firmware version 2.05B11 or later.
3
What packets can be manipulated by exploiting CVE-2019-13154?
Exploiting CVE-2019-13154 allows an attacker to manipulate TCP port settings in the Add Gaming Rule feature.
4
Is authentication required to exploit CVE-2019-13154?
Yes, exploitation of CVE-2019-13154 requires authentication to the TRENDnet TEW-827DRU device.
5
What impact does CVE-2019-13154 have on TRENDnet devices?
CVE-2019-13154 can allow unauthorized command execution, potentially compromising the device's integrity.