Vulnerability Details CVE-2020-14078
TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action wifi_captive_portal_login with a sufficiently long REMOTE_ADDR key.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.038
EPSS Ranking 87.6%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2020-14078
-
cpe:2.3:h:trendnet:tew-827dru:-
-
cpe:2.3:o:trendnet:tew-827dru_firmware:-
-
cpe:2.3:o:trendnet:tew-827dru_firmware:1.04b01
-
cpe:2.3:o:trendnet:tew-827dru_firmware:2.04
-
cpe:2.3:o:trendnet:tew-827dru_firmware:2.04b03
-
cpe:2.3:o:trendnet:tew-827dru_firmware:2.05b11
-
cpe:2.3:o:trendnet:tew-827dru_firmware:2.06b04