← Vulnerability feed

Vulnerability record · CVE-2021-20151 · published 30 December 2021

CVE-2021-20151: Trendnet tew-827dru firmware vulnerability

Trendnet · Tew 827dru Firmware

Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's management software manages web sessions based on IP address rather than verifying client cookies/session tokens/etc. This allows an attacker (whether from a different computer, different web browser on the same machine, etc.) to take over an existing session. This does require the attacker to be able to spoof or take over original IP address of the original user's session.

10.0 CVSS 3.1 Critical EPSS 1.6% · top 25.0% CWE-384 · CWE-384
10.0CVSS 3.1 base score, v2 7.5
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's management software manages web sessions based on IP address rather than verifying client cookies/session tokens/etc. This allows an attacker (whether from a different computer, different web browser on the same machine, etc.) to take over an existing session. This does require the attacker to be able to spoof or take over original IP address of the original user's session.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-20151 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-28354Trendnet tew-827dru firmware command injection vulnerabilityThere is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the …EPSS 2.2%9.8CVE-2021-20149Trendnet tew-827dru firmware incorrect authorization vulnerabilityTrendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient access controls for the WAN interface. The default iptables ruleset for governing…EPSS 1.4%9.8CVE-2021-20155Trendnet tew-827dru firmware hard-coded credentials vulnerabilityTrendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore device configurations via the man…EPSS 1.9%9.8CVE-2021-20158Trendnet tew-827dru firmware missing authentication for critical function vulnerabilityTrendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicous actor to …EPSS 11%9.8CVE-2020-14080Trendnet tew-827dru firmware out-of-bounds write vulnerabilityTRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an unauthenticated user to e…EPSS 2.3%9.8CVE-2019-13276Trendnet tew-827dru firmware out-of-bounds write vulnerabilityTRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains a stack-based buffer overflow in the ssi binary. The overflow allows an unauth…EPSS 2.8%9.8CVE-2019-13278Trendnet tew-827dru firmware os command injection vulnerabilityTRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user input for the setup wizard, a…EPSS 8.8%9.8CVE-2019-13279Trendnet tew-827dru firmware out-of-bounds write vulnerabilityTRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple stack-based buffer overflows when processing user input for the setup…EPSS 2.7%

Source: NIST National Vulnerability Database (record CVE-2021-20151), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.