Vulnerability Details CVE-2020-14080
TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an unauthenticated user to execute arbitrary code by POSTing to apply_sec.cgi via the action ping_test with a sufficiently long ping_ipaddr key.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.038
EPSS Ranking 87.4%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-14080
-
cpe:2.3:h:trendnet:tew-827dru:-
-
cpe:2.3:o:trendnet:tew-827dru_firmware:-
-
cpe:2.3:o:trendnet:tew-827dru_firmware:1.04b01
-
cpe:2.3:o:trendnet:tew-827dru_firmware:2.04
-
cpe:2.3:o:trendnet:tew-827dru_firmware:2.04b03
-
cpe:2.3:o:trendnet:tew-827dru_firmware:2.05b11
-
cpe:2.3:o:trendnet:tew-827dru_firmware:2.06b04