PoC Index

CVE-2021-20160

HIGH 9.0EPSS 3.1%

Trendnet AC2600 TEW-827DRU version 2.08B01 contains a command injection vulnerability in the smb functionality of the device. The username parameter used when configuring smb functionality for the device is vulnerable to command injection as root.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS
3.14% chance of exploitation in the next 30 days, 87th percentile
Published
2021-12-30
Updated
2024-08-03

Proof-of-concept exploits (1)

References

Related