CVE-2022-30328: CSRF
Published Jun 16, 2022
·Updated
An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The username and password setup for the web interface does not require entering the existing password. A malicious user can change the username and password of the interface.
Affected Software
2 affected components
Trendnet Tew-831dr Firmware=1.0_601.130.1.1356
Trendnet TEW-831DR
Event History
Jun 16, 2022
CVE Published
via MITRE·10:04 PM
Data Sourced
via MITRE·10:04 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-30328.
2
What is the severity of CVE-2022-30328?
CVE-2022-30328 has a severity of medium, with a CVSS score of 6.5.
3
Which devices are affected by CVE-2022-30328?
TRENDnet TEW-831DR version 1.0 601.130.1.1356 devices are affected by CVE-2022-30328.
4
What is the impact of CVE-2022-30328?
CVE-2022-30328 allows a malicious user to change the username and password of the web interface without requiring the existing password.
5
Is there a fix available for CVE-2022-30328?
At the time of this advisory, no official fix or patch has been released for CVE-2022-30328. It is recommended to monitor the vendor's website for updates.