First published: Fri Mar 15 2024(Updated: )
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.@smb[%d].username in the apply.cgi interface, thereby gaining root shell privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TRENDnet TEW-827DRU firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28354 is classified as a high severity vulnerability due to the potential for remote command execution.
To mitigate CVE-2024-28354, users should update the TRENDnet TEW-827DRU router to the latest firmware version provided by the vendor.
CVE-2024-28354 affects all TRENDnet TEW-827DRU routers running firmware version 2.10B01.
CVE-2024-28354 is a command injection vulnerability that allows attackers to execute arbitrary commands on the device.
Attackers exploiting CVE-2024-28354 can gain root shell privileges on the TRENDnet TEW-827DRU router.