CVE-2020-14080: Buffer Overflow
Published Jun 15, 2020
·Updated
TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an unauthenticated user to execute arbitrary code by POSTing to applysec.cgi via the action pingtest with a sufficiently long pingipaddr key.
Affected Software
2 affected components
Trendnet TEW-827DRU firmware<=2.06b04
Trendnet TEW-827DRU
Event History
Jun 15, 2020
CVE Published
via MITRE·03:36 AM
Data Sourced
via MITRE·03:36 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-14080?
CVE-2020-14080 is classified as a high-severity vulnerability due to its potential to allow unauthorized code execution.
2
How do I fix CVE-2020-14080?
To fix CVE-2020-14080, update the TRENDnet TEW-827DRU firmware to a version newer than 2.06B04.
3
What devices are affected by CVE-2020-14080?
CVE-2020-14080 affects TRENDnet TEW-827DRU devices running firmware version 2.06B04 or earlier.
4
What type of vulnerability is CVE-2020-14080?
CVE-2020-14080 is a stack-based buffer overflow vulnerability.
5
Can CVE-2020-14080 be exploited remotely?
Yes, CVE-2020-14080 can be exploited remotely by an unauthenticated user via a crafted POST request.