PT-2018-17862 · Trendnet · Trendnet Tew733Gr+2
Published
2018-02-14
·
Updated
2022-12-12
·
CVE-2018-7034
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TRENDnet TEW-751DR version 1.03B03
TRENDnet TEW-752DRU version 1.03B01
TRENDnet TEW-733GR version 1.03B01
Description
The issue allows authentication bypass via an
AUTHORIZED GROUP=1 value. This can be demonstrated by sending a request for "getcfg.php", which is an API endpoint, allowing unauthorized access.Recommendations
For TRENDnet TEW-751DR version 1.03B03, consider disabling access to the "getcfg.php" endpoint until a fix is available.
For TRENDnet TEW-752DRU version 1.03B01, restrict the use of the
AUTHORIZED GROUP variable to prevent unauthorized access.
For TRENDnet TEW-733GR version 1.03B01, avoid using the AUTHORIZED GROUP=1 value in requests to the "getcfg.php" endpoint to minimize the risk of exploitation.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trendnet Tew733Gr
Trendnet Tew-751Dr
Trendnet Tew-752Dru