CVE Feed

    Dashboard / CVE / CVE-2021-28846

    CVE-2021-28846

    A Format String vulnerablity exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service due to a logic bug at address 0x40dcd0 when calling fprintf with "%s: key len = %d, too long\n" format. The two variables seem to be put in the wrong order. The vulnerability could be triggered by sending the POST request to apply_cgi with a long and unknown key in the request body.

    Published:Aug 10, 2021
    Last Modified:Nov 21, 2024
    EPS:Aug 10, 2021
    EPSS Score:0.00308
    CVSS Score:6.5

    Affected Products

    Vendor
    Trendnet
    Product
    Tew-755ap
    Vendor
    Trendnet
    Product
    Tew-755ap2kac
    Vendor
    Trendnet
    Product
    Tew-755ap2kac Firmware
    Vendor
    Trendnet
    Product
    Tew-755ap Firmware
    Vendor
    Trendnet
    Product
    Tew-821dap2kac
    Vendor
    Trendnet
    Product
    Tew-821dap2kac Firmware
    Vendor
    Trendnet
    Product
    Tew-825dap
    Vendor
    Trendnet
    Product
    Tew-825dap Firmware

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High