PT-2019-13234 · Trendnet · Trendnet Tew-827Dru

Published

2019-07-09

·

Updated

2020-08-24

·

CVE-2019-13280

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TRENDnet TEW-827DRU versions up to and including 2.04B03
Description The issue arises from a stack-based buffer overflow that occurs when the device returns an error message about failing to resolve a hostname during a ping or traceroute attempt. This allows an authenticated user to execute arbitrary code. The exploit can be exercised both on the local intranet or remotely if remote administration is enabled.
Recommendations For TRENDnet TEW-827DRU versions up to and including 2.04B03, update the firmware to a version later than 2.04B03 to resolve the issue. As a temporary workaround, consider disabling remote administration to minimize the risk of remote exploitation.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13280

Affected Products

Trendnet Tew-827Dru