First published: Thu Dec 30 2021(Updated: )
Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authentication can be bypassed and a user may view information as Admin by manually browsing to the setup wizard and forcing it to redirect to the desired page.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
TRENDnet TEW-827DRU firmware | =2.08b01 | |
TRENDnet TEW-827DRU | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20150 is rated as a high-severity vulnerability due to the potential for unauthorized information disclosure.
To fix CVE-2021-20150, it is recommended to upgrade the Trendnet TEW-827DRU firmware to the latest version provided by the manufacturer.
CVE-2021-20150 is an information disclosure vulnerability that allows bypassing authentication.
Users of Trendnet AC2600 TEW-827DRU firmware version 2.08B01 are affected by CVE-2021-20150.
Yes, CVE-2021-20150 can be exploited remotely without the need for physical access.