Critical severity10.0NVD Advisory· Published Mar 15, 2024· Updated Jun 17, 2026
CVE-2024-28354
CVE-2024-28354
Description
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.@smb[%d].username in the apply.cgi interface, thereby gaining root shell privileges.
Affected products
3- cpe:2.3:o:trendnet:tew-827dru_firmware:2.10b01:*:*:*:*:*:*:*
- TRENDnet/TEW-827DRU routerdescription
- Range: 2.10B01
Patches
Vulnerability mechanics
References
1- warp-desk-89d.notion.site/TEW-827DRU-c732df50b2454ecaa5451b02f3adda6anvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.