CVE-2019-13278: OS Command Injection
TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user input for the setup wizard, allowing an unauthenticated user to run arbitrary commands on the device. The vulnerability can be exercised on the local intranet or remotely if remote administration is enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13278?
CVE-2019-13278 has a high severity rating due to the potential for unauthorized command execution.
How do I fix CVE-2019-13278?
To mitigate CVE-2019-13278, update the TRENDnet TEW-827DRU firmware to a version above 2.04B03.
Can CVE-2019-13278 be exploited remotely?
Yes, CVE-2019-13278 can be exploited remotely if remote management is enabled on the device.
Who is affected by CVE-2019-13278?
All users of TRENDnet TEW-827DRU firmware versions up to and including 2.04B03 are at risk from CVE-2019-13278.
What devices are vulnerable to CVE-2019-13278?
CVE-2019-13278 affects the TRENDnet TEW-827DRU router specifically running the vulnerable firmware versions.