Impact
The flaw exists in the TRENDNET TEW‑813DRU router firmware 1.01b01 and involves an unknown function used when parsing the /etc/vsftpd.conf file for the vsftpd component. The bug allows an attacker to manipulate the default file permissions that are set for FTP configuration files. As a result, users without proper authorization could potentially read or modify FTP settings, enabling unauthorized access or alteration of the device’s configuration. This is a file‑permission weakness (CWE‑276) that can be exploited remotely, although the attack requires a high degree of complexity and is considered difficult to achieve.
Affected Systems
Only the TRENDNET TEW‑813DRU router running firmware 1.01b01 is affected, according to the CNA data. No other vendors, versions, or products are listed. The device is no longer supported by Trendnet, meaning that no official patch or firmware update is available.
Risk and Exploitability
The CVSS score is 2.3, indicating low severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. The remote attack is possible, but the high complexity and difficult exploitability make real‑world attacks unlikely. Organizations that still use this unsupported model face limited risk, primarily if the device is exposed to untrusted networks. Nonetheless, the lack of a patch and potential for unauthorized configuration changes suggest a low‑to‑moderate threat.
OpenCVE Enrichment