📦 Tew 827dru Firmware

by Trendnet

🔍 What is Tew 827dru Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-28354

CRITICAL CVSS 10.0 Mar 15, 2024

This is a critical command injection vulnerability in TRENDnet TEW-827DRU routers that allows remote attackers to execute arbitrary commands with root privileges. Attackers can exploit this by injecti...

CVE-2021-20149

CRITICAL CVSS 9.8 Dec 30, 2021

This vulnerability allows attackers to bypass IPv4 firewall rules and access all services on Trendnet AC2600 routers via IPv6 WAN interface. It affects Trendnet AC2600 TEW-827DRU routers with insuffic...

CVE-2021-20151

CRITICAL CVSS 10.0 Dec 30, 2021

This vulnerability allows session hijacking on Trendnet AC2600 routers by exploiting IP-based session management instead of proper token verification. Attackers can take over active administrative ses...

CVE-2021-20155

CRITICAL CVSS 9.8 Dec 30, 2021

Trendnet AC2600 TEW-827DRU routers use hardcoded credentials ('12345678') to encrypt configuration backups. This allows attackers to decrypt and potentially modify device configurations, compromising ...

CVE-2021-20158

CRITICAL CVSS 9.8 Dec 30, 2021

This vulnerability allows unauthenticated attackers to change the administrator password on Trendnet AC2600 TEW-827DRU routers. Attackers can exploit a hidden administrative command to bypass authenti...

CVE-2024-36728

HIGH CVSS 8.1 Jun 3, 2024

TRENDnet TEW-827DRU routers contain a stack-based buffer overflow vulnerability in the ssi binary. Authenticated attackers can exploit this by sending specially crafted POST requests to apply.cgi, pot...

CVE-2021-20160

HIGH CVSS 8.8 Dec 30, 2021

This CVE describes a command injection vulnerability in Trendnet AC2600 routers that allows attackers to execute arbitrary commands as root by injecting malicious input into the SMB username parameter...

CVE-2021-20165

HIGH CVSS 8.8 Dec 30, 2021

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Trendnet AC2600 TEW-827DRU routers. Attackers can trick authenticated users into performing unintended actions on the router's w...

CVE-2021-20154

HIGH CVSS 7.5 Dec 30, 2021

Trendnet AC2600 TEW-827DRU routers transmit sensitive information like passwords in cleartext because HTTPS is disabled by default. This affects users who haven't manually enabled HTTPS on their devic...

CVE-2021-20157

HIGH CVSS 7.5 Dec 30, 2021

This vulnerability allows unauthenticated attackers to force affected devices to reboot by exploiting a hidden administrative command. It affects DrayTek Vigor routers and modems, creating denial-of-s...