PT-2021-13810 · Trendnet · Trendnet Ac2600 Tew-827Dru

Published

2021-12-30

·

Updated

2022-01-07

·

CVE-2021-20155

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Trendnet AC2600 TEW-827DRU version 2.08B01
Description: The issue concerns the use of hardcoded credentials in the device. It is possible to backup and restore device configurations via the management web interface. These devices are encrypted using a hardcoded password of "12345678".
Recommendations: For Trendnet AC2600 TEW-827DRU version 2.08B01, consider changing the hardcoded password to a unique and secure password to prevent unauthorized access. As a temporary workaround, restrict access to the management web interface to minimize the risk of exploitation.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-20155

Affected Products

Trendnet Ac2600 Tew-827Dru