CVE-2021-20160: Command Injection
Published Dec 30, 2021
·Updated
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a command injection vulnerability in the smb functionality of the device. The username parameter used when configuring smb functionality for the device is vulnerable to command injection as root.
Affected Software
2 affected components
Trendnet TEW-827DRU firmware=2.08b01
Trendnet TEW-827DRU=2.0
Event History
Dec 30, 2021
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for Trendnet AC2600 TEW-827DRU?
The vulnerability ID for Trendnet AC2600 TEW-827DRU is CVE-2021-20160.
2
What is the severity of CVE-2021-20160?
The severity of CVE-2021-20160 is critical with a CVSS score of 8.8.
3
What is the affected software for CVE-2021-20160?
The affected software for CVE-2021-20160 is Trendnet AC2600 TEW-827DRU version 2.08B01.
4
What is the description of CVE-2021-20160?
CVE-2021-20160 is a command injection vulnerability in the smb functionality of Trendnet AC2600 TEW-827DRU version 2.08B01.
5
How can I fix CVE-2021-20160?
To fix CVE-2021-20160, apply the latest firmware update provided by TRENDnet.