CVE-2021-20163: Medium severity trendnet tew-827dru vulnerability
Published Dec 30, 2021
·Updated
Trendnet AC2600 TEW-827DRU version 2.08B01 leaks information via the ftp web page. Usernames and passwords for all ftp users are revealed in plaintext on the ftpserver.asp page.
Affected Software
2 affected components
Trendnet TEW-827DRU firmware=2.08b01
Trendnet TEW-827DRU=2.0
Event History
Dec 30, 2021
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-20163?
CVE-2021-20163 is classified as a medium severity vulnerability due to the exposure of sensitive information.
2
How do I fix CVE-2021-20163?
To fix CVE-2021-20163, you should update the firmware of the Trendnet TEW-827DRU to the latest version provided by the vendor.
3
What information is leaked due to CVE-2021-20163?
CVE-2021-20163 leaks usernames and passwords for all FTP users in plaintext on the ftpserver.asp page.
4
Which versions of Trendnet TEW-827DRU are affected by CVE-2021-20163?
CVE-2021-20163 affects Trendnet TEW-827DRU with firmware version 2.08B01.
5
Is there a workaround for CVE-2021-20163?
A recommended workaround for CVE-2021-20163 is to disable FTP access until the firmware can be updated.