Vulnerability Description
An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The username and password setup for the web interface does not require entering the existing password. A malicious user can change the username and password of the interface.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trendnet | Tew-831Dr Firmware | 1.0_601.130.1.1356 |
| Trendnet | Tew-831Dr | - |
Related Weaknesses (CWE)
References
- https://research.nccgroup.com/2022/06/10/technical-advisory-multiple-vulnerabiliThird Party Advisory
- https://research.nccgroup.com/?research=Technical+advisoriesThird Party Advisory
- https://research.nccgroup.com/2022/06/10/technical-advisory-multiple-vulnerabiliThird Party Advisory
- https://research.nccgroup.com/?research=Technical+advisoriesThird Party Advisory
FAQ
What is CVE-2022-30328?
CVE-2022-30328 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The username and password setup for the web interface does not require entering the existing password. A malicious user can change ...
How severe is CVE-2022-30328?
CVE-2022-30328 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-30328?
Check the references section above for vendor advisories and patch information. Affected products include: Trendnet Tew-831Dr Firmware, Trendnet Tew-831Dr.