CVE-2021-20161: High severity trendnet tew-827dru vulnerability
Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient protections for the UART functionality. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection. No username or password is required and the user is given a root shell with full control of the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20161?
CVE-2021-20161 has a high severity level due to the potential for unauthorized access to the device's root shell.
How do I fix CVE-2021-20161?
To fix CVE-2021-20161, ensure physical security of the device and contact Trendnet for any firmware updates.
What type of access does CVE-2021-20161 allow?
CVE-2021-20161 allows an attacker with physical access to gain root shell access through the UART port.
Is the CVE-2021-20161 vulnerability hardware-specific?
CVE-2021-20161 specifically affects the Trendnet TEW-827DRU version 2.08B01 firmware.
Can CVE-2021-20161 be exploited remotely?
No, CVE-2021-20161 requires physical access to the device for exploitation.