PT-2022-2962 · Trendnet · Trendnet Tew-831Dr

Published

2022-06-16

·

Updated

2022-06-27

·

CVE-2022-30325

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TRENDnet TEW-831DR version 1.0 601.130.1.1356
Description An issue was found where the default pre-shared key for the Wi-Fi networks is the same for every router except for the last four digits. This allows an attacker within range of the Wi-Fi network to guess or brute-force the device default pre-shared key for both 2.4 GHz and 5 GHz networks. The vulnerability is related to the use of a hardcoded cryptographic key, which can be exploited by a remote attacker to obtain the encryption key.
Recommendations For TRENDnet TEW-831DR version 1.0 601.130.1.1356, consider changing the default pre-shared key to a unique and strong key to prevent guessing or brute-forcing attacks. As a temporary workaround, restrict access to the Wi-Fi network to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

XSS

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2022-03590
BDU:2022-03591
BDU:2022-03592
BDU:2022-03593
BDU:2022-03594
CVE-2022-30325

Affected Products

Trendnet Tew-831Dr