First published: Thu Dec 30 2021(Updated: )
Trendnet AC2600 TEW-827DRU version 2.08B01 lacks proper authentication to the bittorrent functionality. If enabled, anyone is able to visit and modify settings and files via the Bittorent web client by visiting: http://192.168.10.1:9091/transmission/web/
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
TRENDnet TEW-827DRU firmware | =2.08b01 | |
TRENDnet TEW-827DRU | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20152 has a medium severity rating due to improper authentication allowing unauthorized access to sensitive functionalities.
To fix CVE-2021-20152, you should disable the BitTorrent functionality or update the firmware of the Trendnet AC2600 TEW-827DRU to a patched version.
CVE-2021-20152 affects the Trendnet TEW-827DRU firmware version 2.08B01.
Yes, attackers can exploit CVE-2021-20152 remotely by accessing the BitTorrent web client without proper authentication.
The risks associated with CVE-2021-20152 include unauthorized access to and modification of settings and files via the BitTorrent web client.