There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.@smb[%d].username in the apply.cgi interface, thereby gaining root shell privileges.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 01 Apr 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Trendnet
Trendnet tew-827dru
Trendnet tew-827dru Firmware
CPEs cpe:2.3:h:trendnet:tew-827dru:-:*:*:*:*:*:*:*
cpe:2.3:o:trendnet:tew-827dru_firmware:2.10b01:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-827dru
Trendnet tew-827dru Firmware

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T20:20:36.382Z

Reserved: 2024-03-08T00:00:00

Link: CVE-2024-28354

cve-icon Vulnrichment

Updated: 2024-08-02T00:56:56.444Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-15T08:15:07.093

Modified: 2025-04-01T16:14:18.653

Link: CVE-2024-28354

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.