CVE Database
/

CVE-2021-20156

Back to search

CVE-2021-20156

Published: Dec 30, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

Trendnet AC2600 TEW-827DRU version 2.08B01 contains an improper access control configuration that could allow for a malicious firmware update. It is possible to manually install firmware that may be malicious in nature as there does not appear to be any signature validation done to determine if it is from a known and trusted source. This includes firmware updates that are done via the automated "check for updates" in the admin interface. If an attacker is able to masquerade as the update server, the device will not verify that the firmware updates downloaded are legitimate.

VendorProductVersions

n/a

Trendnet AC2600 TEW-827DRU

affected
2.08B01

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now