First published: Mon Jun 15 2020(Updated: )
TRENDnet TEW-827DRU devices through 2.06B04 contain multiple command injections in apply.cgi via the action pppoe_connect, ru_pppoe_connect, or dhcp_connect with the key wan_ifname (or wan0_dns), allowing an authenticated user to run arbitrary commands on the device.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TRENDnet TEW-827DRU firmware | <=2.06b04 | |
TRENDnet TEW-827DRU |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14075 is classified as a medium severity vulnerability due to its potential for exploitation through command injection.
To fix CVE-2020-14075, upgrade your TRENDnet TEW-827DRU firmware to a version above 2.06B04.
CVE-2020-14075 affects TRENDnet TEW-827DRU devices running firmware version 2.06B04 or earlier.
CVE-2020-14075 can facilitate command injection attacks, allowing authenticated users to execute arbitrary commands on affected devices.
No, CVE-2020-14075 requires an authenticated user to exploit the command injection vulnerabilities.