PT-2021-13816 · Trendnet · Trendnet Ac2600 Tew-827Dru
Jimi Sebree
·
Published
2021-12-30
·
Updated
2022-07-12
·
CVE-2021-20161
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Trendnet AC2600 TEW-827DRU version 2.08B01
Description:
The issue concerns insufficient protections for the UART functionality. A malicious actor with physical access to the device can connect to the UART port via a serial connection, gaining a root shell with full control of the device without requiring a username or password.
Recommendations:
For Trendnet AC2600 TEW-827DRU version 2.08B01, as a temporary workaround, consider restricting physical access to the device to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trendnet Ac2600 Tew-827Dru