CVE-2020-14077: Buffer Overflow
Published Jun 15, 2020
·Updated
TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action setstaenrolleepinwifi1 (or setstaenrolleepinwifi0) with a sufficiently long wpsstaenrolleepin key.
Affected Software
2 affected components
Trendnet TEW-827DRU firmware<=2.06b04
Trendnet TEW-827DRU
Event History
Jun 15, 2020
CVE Published
via MITRE·03:36 AM
Data Sourced
via MITRE·03:36 AM
Description
Frequently Asked Questions
1
How does CVE-2020-14077 impact TRENDnet TEW-827DRU devices?
It allows an authenticated user to execute arbitrary code by exploiting a stack-based buffer overflow in the ssi binary through POSTing to apply.cgi with a long wps_sta_ parameter.
2
What is the severity of CVE-2020-14077?
The severity of CVE-2020-14077 is high with a CVSS score of 8.8.
3
How can I mitigate CVE-2020-14077 on TRENDnet TEW-827DRU devices?
To mitigate CVE-2020-14077, users should update the device firmware to a non-vulnerable version provided by the vendor.