Vulnerability Description
TRENDnet TEW-751DR v1.03B03, TEW-752DRU v1.03B01, and TEW733GR v1.03B01 devices allow authentication bypass via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trendnet | Tew-751Dr Firmware | 1.03b03 |
| Trendnet | Tew-751Dr | - |
| Trendnet | Tew-752Dru Firmware | 1.03b01 |
| Trendnet | Tew-752Dru | - |
| Trendnet | Tew733Gr Firmware | 1.03b01 |
| Trendnet | Tew733Gr | - |
Related Weaknesses (CWE)
References
- https://blogs.securiteam.com/index.php/archives/3627ExploitThird Party Advisory
- https://blogs.securiteam.com/index.php/archives/3627ExploitThird Party Advisory
FAQ
What is CVE-2018-7034?
CVE-2018-7034 is a vulnerability with a CVSS score of 7.5 (HIGH). TRENDnet TEW-751DR v1.03B03, TEW-752DRU v1.03B01, and TEW733GR v1.03B01 devices allow authentication bypass via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.
How severe is CVE-2018-7034?
CVE-2018-7034 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-7034?
Check the references section above for vendor advisories and patch information. Affected products include: Trendnet Tew-751Dr Firmware, Trendnet Tew-751Dr, Trendnet Tew-752Dru Firmware, Trendnet Tew-752Dru, Trendnet Tew733Gr Firmware.