Impact
The vulnerability arises from an unsafe use of the strcpy function in the /cgi-bin/wan.cgi script of the TRENDnet TEW-823DRU. By manipulating the wan_l2tp_password argument, an attacker sends a payload that overflows the stack and can execute arbitrary code. The flaw exists in firmware 1.1.02b01 and can be triggered remotely over the web interface, giving an attacker the ability to take control of the device or alter its configuration, compromising confidentiality, integrity, and availability.
Affected Systems
Affected devices are TRENDnet TEW-823DRU routers running firmware version 1.1.02b01. The vulnerability is in the NVRAM component exposed via the /cgi-bin/wan.cgi page, and impacts any unit that has the L2TP WAN feature enabled.
Risk and Exploitability
The CVSS score of 9.4 indicates a high severity vulnerability. The exploit is publicly available and can be launched remotely without additional credentials or local access. While an EPSS score is not available, the lack of KEV listing does not reduce the risk, as the flaw remains actionable. Attackers can achieve remote code execution by sending a specially crafted password string to the wan_l2tp_password parameter, leading to arbitrary code execution on the device.
OpenCVE Enrichment