Description
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.@smb[%d].username in the apply.cgi interface, thereby gaining root shell privileges.
Published: 2024-03-15
Score: 10.0 Critical
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Apr 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Trendnet
Trendnet tew-827dru
Trendnet tew-827dru Firmware
CPEs cpe:2.3:h:trendnet:tew-827dru:-:*:*:*:*:*:*:*
cpe:2.3:o:trendnet:tew-827dru_firmware:2.10b01:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-827dru
Trendnet tew-827dru Firmware

Subscriptions

Trendnet Tew-827dru Tew-827dru Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T20:20:36.382Z

Reserved: 2024-03-08T00:00:00.000Z

Link: CVE-2024-28354

cve-icon Vulnrichment

Updated: 2024-08-02T00:56:56.444Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-15T08:15:07.093

Modified: 2025-04-01T16:14:18.653

Link: CVE-2024-28354

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses