Description
A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of the file /etc/bftpd.conf of the component bftpd. The manipulation of the argument USERLIMIT_GLOBAL results in allocation of resources. It is possible to launch the attack remotely. This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-08-14
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to manipulate the USERLIMIT_GLOBAL parameter in /etc/bftpd.conf, causing the bftpd service to allocate an abnormal amount of resources. This uncontrolled resource consumption (CWE-400) can exhaust device memory or other limited resources, leading to a denial of service that renders the device unresponsive or slow. The entry is also classified under CWE-770, indicating excessive use of third‑party resources when the application does not guard against it.

Affected Systems

The affected model is TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. Since the device has been discontinued and is no longer supported by the vendor, no patch or update has been released. The flaw resides in the bftpd daemon, which handles FTP traffic, and can be triggered remotely through the management interface that permits configuration changes.

Risk and Exploitability

The CVSS base score is 6.9, reflecting moderate risk. The EPSS score is unavailable, so there are no publicly reported exploitation statistics at this time, and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw remotely by sending a crafted configuration request to bftpd; however, because the product is end‑of‑life, the likelihood of attack for a vendor’s IP address is uncertain. Still, the potential impact on availability warrants defensive action.

Generated by OpenCVE AI on August 14, 2026 at 15:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Replace or decommission the TRENDnet TEW-816DRM device and transition to a supported product or security‑managed alternative.
  • If replacement is not possible, disable the bftpd service or block remote access to the configuration interface to eliminate the remote‑attack surface.
  • Apply all available system hardening measures, such as restricting remote configuration ports, using firewall rules, and monitoring for DoS indicators.

Generated by OpenCVE AI on August 14, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of the file /etc/bftpd.conf of the component bftpd. The manipulation of the argument USERLIMIT_GLOBAL results in allocation of resources. It is possible to launch the attack remotely. This vulnerability only affects products that are no longer supported by the maintainer.
Title TRENDnet TEW-816DRM bftpd bftpd.conf allocation of resources
First Time appeared Trendnet
Trendnet tew-816drm
Weaknesses CWE-400
CWE-770
CPEs cpe:2.3:a:trendnet:tew-816drm:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-816drm
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Trendnet Tew-816drm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-14T15:11:46.264Z

Reserved: 2026-08-14T07:01:57.646Z

Link: CVE-2026-19830

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T14:16:51.317

Modified: 2026-08-14T14:16:51.317

Link: CVE-2026-19830

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T15:30:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling