PT-2014-1993 · Trendnet · Trendnet Tew-823Dru
Hacking Com Tapioca
·
Published
2014-10-30
·
Updated
2018-01-26
·
CVE-2014-8579
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TRENDnet TEW-823DRU versions prior to 1.00b36
Description
The issue is related to a hardcoded password for the root account, specifically
kcodeskcodes, which can be exploited by remote attackers to gain access via an FTP session. This hardcoded password makes it easier for attackers to obtain unauthorized access.Recommendations
For TRENDnet TEW-823DRU versions prior to 1.00b36, update the firmware to version 1.00b36 or later to resolve the issue. As a temporary workaround, consider changing the root account password to a unique and secure value until the firmware can be updated. Restrict access to FTP sessions to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trendnet Tew-823Dru