CVE-2021-28846
A Format String vulnerablity exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service due to a logic bug at address 0x40dcd0 when calling fprintf with "%s: key len = %d, too long\n" format. The two variables seem to be put in the wrong order. The vulnerability could be triggered by sending the POST request to apply_cgi with a long and unknown key in the request body.
Published:Aug 10, 2021
Last Modified:Nov 21, 2024
EPS:Aug 10, 2021
EPSS Score:0.00308
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Trendnet
Product
Tew-755ap
Trendnet
Tew-755ap
Vendor
Trendnet
Product
Tew-755ap2kac
Trendnet
Tew-755ap2kac
Vendor
Trendnet
Product
Tew-755ap2kac Firmware
Trendnet
Tew-755ap2kac Firmware
Vendor
Trendnet
Product
Tew-755ap Firmware
Trendnet
Tew-755ap Firmware
Vendor
Trendnet
Product
Tew-821dap2kac
Trendnet
Tew-821dap2kac
Vendor
Trendnet
Product
Tew-821dap2kac Firmware
Trendnet
Tew-821dap2kac Firmware
Vendor
Trendnet
Product
Tew-825dap
Trendnet
Tew-825dap
Vendor
Trendnet
Product
Tew-825dap Firmware
Trendnet
Tew-825dap Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
