Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-28354


There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.@smb[%d].username in the apply.cgi interface, thereby gaining root shell privileges.


Published

2024-03-15T08:15:07.093

Last Modified

2025-04-01T16:14:18.653

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 10.0 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System trendnet tew-827dru_firmware 2.10b01 Yes
Hardware trendnet tew-827dru - No

References