CVE-2024-28354: Command Injection
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.@smb[%d].username in the apply.cgi interface, thereby gaining root shell privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28354?
CVE-2024-28354 is classified as a high severity vulnerability due to the potential for remote command execution.
How do I fix CVE-2024-28354?
To mitigate CVE-2024-28354, users should update the TRENDnet TEW-827DRU router to the latest firmware version provided by the vendor.
Who is affected by CVE-2024-28354?
CVE-2024-28354 affects all TRENDnet TEW-827DRU routers running firmware version 2.10B01.
What type of vulnerability is CVE-2024-28354?
CVE-2024-28354 is a command injection vulnerability that allows attackers to execute arbitrary commands on the device.
What can attackers do with CVE-2024-28354?
Attackers exploiting CVE-2024-28354 can gain root shell privileges on the TRENDnet TEW-827DRU router.