trendnet TEW-825DAP Security Vulnerabilities

6 Vulnerabilities
Description

Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service by sending the POST request to apply_cgi via the lang action without a language key.

Impacted versions: -

Base Score: 0.0, Severity: NA, ID: CVE-2021-28845, Last Modified: 2021-08-10T20:15:00Z

References

Advisory

Modemly Security Checklist

TRENDnet-TEW-825DAP-router-setup

A Format String vulnerablity exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service due to a logic bug at address 0x40dcd0 when calling fprintf with "%s: key len = %d, too long\n" format. The two variables seem to be put in the wrong order. The vulnerability could be triggered by sending the POST request to apply_cgi with a long and unknown key in the request body.

Impacted versions: -

Base Score: 0.0, Severity: NA, ID: CVE-2021-28846, Last Modified: 2021-08-10T20:15:00Z

References

Advisory

Modemly Security Checklist

TRENDnet-TEW-825DAP-router-setup

Null Pointer Dereference vulnerability in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service by sending a POST request to apply_cgi via an action ping_test without a ping_ipaddr key.

Impacted versions: -

Base Score: 0.0, Severity: NA, ID: CVE-2021-28841, Last Modified: 2021-08-10T19:15:00Z

References

Advisory

Modemly Security Checklist

TRENDnet-TEW-825DAP-router-setup

Null Pointer Deference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial os service by sending the POST request to apply_cgi via action do_graph_auth without login_name key.

Impacted versions: -

Base Score: 0.0, Severity: NA, ID: CVE-2021-28842, Last Modified: 2021-08-10T19:15:00Z

References

Advisory

Modemly Security Checklist

TRENDnet-TEW-825DAP-router-setup

Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03 by sending the POST request to apply_cgi with unknown an action name.

Impacted versions: -

Base Score: 0.0, Severity: NA, ID: CVE-2021-28843, Last Modified: 2021-08-10T19:15:00Z

References

Advisory

Modemly Security Checklist

TRENDnet-TEW-825DAP-router-setup

Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03 by sending the POST request to an apply_cgi via action do_graph_auth without a session_id key.

Impacted versions: -

Base Score: 0.0, Severity: NA, ID: CVE-2021-28844, Last Modified: 2021-08-10T19:15:00Z

References

Advisory

Modemly Security Checklist

TRENDnet-TEW-825DAP-router-setup
Free Home-Networking Courses, tutorials and security checklists

USAGE: Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.