← Vulnerability feed

Vulnerability record · CVE-2021-20150 · published 30 December 2021

CVE-2021-20150: Trendnet tew-827dru firmware missing authentication for critical function vulnerability

Trendnet · Tew 827dru Firmware

Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authentication can be bypassed and a user may view information as Admin by manually browsing to the setup wizard and forcing it to redirect to the desired page.

5.3 CVSS 3.1 Medium EPSS 40% · top 1.4% CWE-306 · Missing authentication for critical function
5.3CVSS 3.1 base score, v2 5.0
40%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authentication can be bypassed and a user may view information as Admin by manually browsing to the setup wizard and forcing it to redirect to the desired page.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.tenable.com/security/research/tra-2021-54 MitigationThird Party Advisory
https://www.tenable.com/security/research/tra-2021-54 MitigationThird Party Advisory

Track CVE-2021-20150 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-28354Trendnet tew-827dru firmware command injection vulnerabilityThere is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the …EPSS 2.2%10.0CVE-2021-20151Trendnet tew-827dru firmware vulnerabilityTrendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's management software manages web ses…EPSS 1.6%9.8CVE-2021-20149Trendnet tew-827dru firmware incorrect authorization vulnerabilityTrendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient access controls for the WAN interface. The default iptables ruleset for governing…EPSS 1.4%9.8CVE-2021-20155Trendnet tew-827dru firmware hard-coded credentials vulnerabilityTrendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore device configurations via the man…EPSS 1.9%9.8CVE-2021-20158Trendnet tew-827dru firmware missing authentication for critical function vulnerabilityTrendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicous actor to …EPSS 11%9.8CVE-2020-14080Trendnet tew-827dru firmware out-of-bounds write vulnerabilityTRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an unauthenticated user to e…EPSS 2.3%9.8CVE-2019-13276Trendnet tew-827dru firmware out-of-bounds write vulnerabilityTRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains a stack-based buffer overflow in the ssi binary. The overflow allows an unauth…EPSS 2.8%9.8CVE-2019-13278Trendnet tew-827dru firmware os command injection vulnerabilityTRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user input for the setup wizard, a…EPSS 8.8%

Source: NIST National Vulnerability Database (record CVE-2021-20150), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.