CVE-2021-20149
Last modified
CVE-2021-20149 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient access controls for the WAN interface. The default iptables ruleset for governing access to services on the device only apply to IPv4. EPSS estimates a 1.43% chance of exploitation in the next 30 days.
Description
Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient access controls for the WAN interface. The default iptables ruleset for governing access to services on the device only apply to IPv4. All services running on the devices are accessible via the WAN interface via IPv6 by default.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Trendnet | Tew-827dru Firmware | 2.08b01 |
References
- https://www.tenable.com/security/research/tra-2021-54Third Party Advisory
- https://www.tenable.com/security/research/tra-2021-54Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-20149?
How severe is CVE-2021-20149?
How do I fix CVE-2021-20149?
Are you affected by CVE-2021-20149?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
