CVE-2021-20159: Command Injection
Published Dec 30, 2021
·Updated
Trendnet AC2600 TEW-827DRU version 2.08B01 is vulnerable to command injection. The system log functionality of the firmware allows for command injection as root by supplying a malformed parameter.
Affected Software
2 affected components
Trendnet TEW-827DRU firmware=2.08b01
Trendnet TEW-827DRU=2.0
Event History
Dec 30, 2021
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-20159.
2
What is the severity of CVE-2021-20159?
The severity of CVE-2021-20159 is critical.
3
Which software versions are affected by CVE-2021-20159?
Trendnet AC2600 TEW-827DRU version 2.08B01 is affected by CVE-2021-20159.
4
How does CVE-2021-20159 manifest?
CVE-2021-20159 manifests as a command injection vulnerability in the system log functionality of Trendnet AC2600 TEW-827DRU firmware version 2.08B01.
5
Is there a fix available for CVE-2021-20159?
At the moment, there is no known fix available for CVE-2021-20159. It is recommended to contact the vendor for further information.