Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-36728


TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action vlan_setting with a sufficiently long dns1 or dns 2 key.


Published

2024-06-03T14:15:09.330

Last Modified

2025-04-01T18:21:29.640

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-121

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System trendnet tew-827dru_firmware ≤ 2.06b04 Yes
Hardware trendnet tew-827dru - No

References