Vulnerability Details CVE-2020-14081
TRENDnet TEW-827DRU devices through 2.06B04 contain multiple command injections in apply.cgi via the action send_log_email with the key auth_acname (or auth_passwd), allowing an authenticated user to run arbitrary commands on the device.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.075
EPSS Ranking 91.3%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 9.0
Products affected by CVE-2020-14081
-
cpe:2.3:h:trendnet:tew-827dru:-
-
cpe:2.3:o:trendnet:tew-827dru_firmware:-
-
cpe:2.3:o:trendnet:tew-827dru_firmware:1.04b01
-
cpe:2.3:o:trendnet:tew-827dru_firmware:2.04
-
cpe:2.3:o:trendnet:tew-827dru_firmware:2.04b03
-
cpe:2.3:o:trendnet:tew-827dru_firmware:2.05b11
-
cpe:2.3:o:trendnet:tew-827dru_firmware:2.06b04