First published: Thu Dec 30 2021(Updated: )
Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses credentials for the smb functionality of the device. Usernames and passwords for all smb users are revealed in plaintext on the smbserver.asp page.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
TRENDnet TEW-827DRU firmware | =2.08b01 | |
TRENDnet TEW-827DRU | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20164 reveals usernames and passwords for all SMB users in plaintext on the smbserver.asp page of Trendnet AC2600 TEW-827DRU firmware version 2.08B01.
CVE-2021-20164 is considered a high-severity vulnerability due to the exposure of sensitive credentials.
To fix CVE-2021-20164, users should upgrade the firmware of the Trendnet AC2600 TEW-827DRU to a version that addresses this vulnerability.
CVE-2021-20164 specifically affects Trendnet AC2600 TEW-827DRU firmware version 2.08B01.
The risks associated with CVE-2021-20164 include unauthorized access to the SMB functionality of the device, leading to potential data breaches.