First published: Thu Dec 30 2021(Updated: )
Trendnet AC2600 TEW-827DRU version 2.08B01 leaks information via the ftp web page. Usernames and passwords for all ftp users are revealed in plaintext on the ftpserver.asp page.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
TRENDnet TEW-827DRU firmware | =2.08b01 | |
TRENDnet TEW-827DRU | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20163 is classified as a medium severity vulnerability due to the exposure of sensitive information.
To fix CVE-2021-20163, you should update the firmware of the Trendnet TEW-827DRU to the latest version provided by the vendor.
CVE-2021-20163 leaks usernames and passwords for all FTP users in plaintext on the ftpserver.asp page.
CVE-2021-20163 affects Trendnet TEW-827DRU with firmware version 2.08B01.
A recommended workaround for CVE-2021-20163 is to disable FTP access until the firmware can be updated.