PT-2022-2962 · Trendnet · Trendnet Tew-831Dr
Published
2022-06-16
·
Updated
2022-06-27
·
CVE-2022-30325
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TRENDnet TEW-831DR version 1.0 601.130.1.1356
Description
An issue was found where the default pre-shared key for the Wi-Fi networks is the same for every router except for the last four digits. This allows an attacker within range of the Wi-Fi network to guess or brute-force the device default pre-shared key for both 2.4 GHz and 5 GHz networks. The vulnerability is related to the use of a hardcoded cryptographic key, which can be exploited by a remote attacker to obtain the encryption key.
Recommendations
For TRENDnet TEW-831DR version 1.0 601.130.1.1356, consider changing the default pre-shared key to a unique and strong key to prevent guessing or brute-forcing attacks. As a temporary workaround, restrict access to the Wi-Fi network to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
XSS
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trendnet Tew-831Dr