CVE-2021-20156
Last modified
CVE-2021-20156 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Trendnet AC2600 TEW-827DRU version 2.08B01 contains an improper access control configuration that could allow for a malicious firmware update. It is possible to manually install firmware that may be malicious in nature as there does not appear to be any signature validation done to determine if it is from a known and trusted source. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
Trendnet AC2600 TEW-827DRU version 2.08B01 contains an improper access control configuration that could allow for a malicious firmware update. It is possible to manually install firmware that may be malicious in nature as there does not appear to be any signature validation done to determine if it is from a known and trusted source. This includes firmware updates that are done via the automated "check for updates" in the admin interface. If an attacker is able to masquerade as the update server, the device will not verify that the firmware updates downloaded are legitimate.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Trendnet | Tew-827dru Firmware | 2.08b01 |
References
- https://www.tenable.com/security/research/tra-2021-54Third Party Advisory
- https://www.tenable.com/security/research/tra-2021-54Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-20156?
How severe is CVE-2021-20156?
How do I fix CVE-2021-20156?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-20150Trendnet AC2600 TEW-827DRU version 2.08B01 improperly disclo…5.3
- CVE-2021-20151Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw i…10
- CVE-2021-20152Trendnet AC2600 TEW-827DRU version 2.08B01 lacks proper auth…6.5
- CVE-2021-20153Trendnet AC2600 TEW-827DRU version 2.08B01 contains a symlin…6.8
- CVE-2021-20154Trendnet AC2600 TEW-827DRU version 2.08B01 contains an secur…7.5
- CVE-2021-20155Trendnet AC2600 TEW-827DRU version 2.08B01 makes use of hard…9.8
- CVE-2021-20157It is possible for an unauthenticated, malicious user to for…7.5
- CVE-2021-20158Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authe…9.8
- CVE-2021-20159Trendnet AC2600 TEW-827DRU version 2.08B01 is vulnerable to …8.8
- CVE-2021-2016Vulnerability in the MySQL Server product of Oracle MySQL (c…4.9
- CVE-2021-20160Trendnet AC2600 TEW-827DRU version 2.08B01 contains a comman…8.8
- CVE-2021-20161Trendnet AC2600 TEW-827DRU version 2.08B01 does not have suf…6.8
Are you affected by CVE-2021-20156?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
