Vulnerability Description
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.config.smb_admin_name in the apply.cgi interface, thereby gaining root shell privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trendnet | Tew-827Dru Firmware | 2.10b01 |
| Trendnet | Tew-827Dru | - |
Related Weaknesses (CWE)
References
- https://warp-desk-89d.notion.site/TEW-827DRU-5c40fb20572148f0b00f329d69273791ExploitThird Party Advisory
- https://warp-desk-89d.notion.site/TEW-827DRU-5c40fb20572148f0b00f329d69273791ExploitThird Party Advisory
FAQ
What is CVE-2024-28353?
CVE-2024-28353 is a vulnerability with a CVSS score of 8.8 (HIGH). There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.config.smb_admin_nam...
How severe is CVE-2024-28353?
CVE-2024-28353 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-28353?
Check the references section above for vendor advisories and patch information. Affected products include: Trendnet Tew-827Dru Firmware, Trendnet Tew-827Dru.