Vulnerability Details CVE-2024-36728
TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action vlan_setting with a sufficiently long dns1 or dns 2 key.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.1%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2024-36728
-
cpe:2.3:h:trendnet:tew-827dru:-
-
cpe:2.3:o:trendnet:tew-827dru_firmware:-
-
cpe:2.3:o:trendnet:tew-827dru_firmware:1.04b01
-
cpe:2.3:o:trendnet:tew-827dru_firmware:2.04
-
cpe:2.3:o:trendnet:tew-827dru_firmware:2.04b03
-
cpe:2.3:o:trendnet:tew-827dru_firmware:2.05b11
-
cpe:2.3:o:trendnet:tew-827dru_firmware:2.06b04