CVSS v3
9.8
CRITICAL
EPSS Score
50.5%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user input for the setup wizard, allowing an unauthenticated user to run arbitrary commands on the device. The vulnerability can be exercised on the local intranet or remotely if remote administration is enabled.
TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user input for the setup wizard, allowing an unauthenticated user to run arbitrary commands on the device. The vulnerability can be exercised on the local intranet or remotely if remote administration is enabled.
Active exploitation of CVE-2019-13278 has not been confirmed. The EPSS score is 50.5%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2019-13278 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).