← Vulnerability feed

Vulnerability record · CVE-2021-20149 · published 30 December 2021

CVE-2021-20149: Trendnet tew-827dru firmware incorrect authorization vulnerability

Trendnet · Tew 827dru Firmware

Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient access controls for the WAN interface. The default iptables ruleset for governing access to services on the device only apply to IPv4. All services running on the devices are accessible via the WAN interface via IPv6 by default.

9.8 CVSS 3.1 Critical EPSS 1.4% · top 27.8% CWE-863 · Incorrect authorization
9.8CVSS 3.1 base score, v2 7.5
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient access controls for the WAN interface. The default iptables ruleset for governing access to services on the device only apply to IPv4. All services running on the devices are accessible via the WAN interface via IPv6 by default.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-20149 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-28354Trendnet tew-827dru firmware command injection vulnerabilityThere is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the …EPSS 2.2%10.0CVE-2021-20151Trendnet tew-827dru firmware vulnerabilityTrendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's management software manages web ses…EPSS 1.6%9.8CVE-2021-20155Trendnet tew-827dru firmware hard-coded credentials vulnerabilityTrendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore device configurations via the man…EPSS 1.9%9.8CVE-2021-20158Trendnet tew-827dru firmware missing authentication for critical function vulnerabilityTrendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicous actor to …EPSS 11%9.8CVE-2020-14080Trendnet tew-827dru firmware out-of-bounds write vulnerabilityTRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an unauthenticated user to e…EPSS 2.3%9.8CVE-2019-13276Trendnet tew-827dru firmware out-of-bounds write vulnerabilityTRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains a stack-based buffer overflow in the ssi binary. The overflow allows an unauth…EPSS 2.8%9.8CVE-2019-13278Trendnet tew-827dru firmware os command injection vulnerabilityTRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user input for the setup wizard, a…EPSS 8.8%9.8CVE-2019-13279Trendnet tew-827dru firmware out-of-bounds write vulnerabilityTRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple stack-based buffer overflows when processing user input for the setup…EPSS 2.7%

Source: NIST National Vulnerability Database (record CVE-2021-20149), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.