Impact
The vulnerability allows an attacker to manipulate the USERLIMIT_GLOBAL parameter in /etc/bftpd.conf, causing the bftpd service to allocate an abnormal amount of resources. This uncontrolled resource consumption (CWE-400) can exhaust device memory or other limited resources, leading to a denial of service that renders the device unresponsive or slow. The entry is also classified under CWE-770, indicating excessive use of third‑party resources when the application does not guard against it.
Affected Systems
The affected model is TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. Since the device has been discontinued and is no longer supported by the vendor, no patch or update has been released. The flaw resides in the bftpd daemon, which handles FTP traffic, and can be triggered remotely through the management interface that permits configuration changes.
Risk and Exploitability
The CVSS base score is 6.9, reflecting moderate risk. The EPSS score is unavailable, so there are no publicly reported exploitation statistics at this time, and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw remotely by sending a crafted configuration request to bftpd; however, because the product is end‑of‑life, the likelihood of attack for a vendor’s IP address is uncertain. Still, the potential impact on availability warrants defensive action.
OpenCVE Enrichment