CVE-2021-20149

CRITICAL
9.8CVSS v3
7.5CVSS v2
0.71% EPSS (exploit probability)
CWE-863CWE

Description

Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient access controls for the WAN interface. The default iptables ruleset for governing access to services on the device only apply to IPv4. All services running on the devices are accessible via the WAN interface via IPv6 by default.

CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected routers (1)

VendorModelMatched viaAffected versionsFixed inPatch Status
TRENDnet TRENDnet TEW-827DRU Unpatched

External references