CVE-2020-14077
15.06.2020, 04:15
TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action set_sta_enrollee_pin_wifi1 (or set_sta_enrollee_pin_wifi0) with a sufficiently long wps_sta_enrollee_pin key.Enginsight
Vendor | Product | Version |
---|---|---|
trendnet | tew-827dru_firmware | 𝑥 ≤ 2.06b04 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References