CRITICAL

CVE-2019-13278

CVSS v3

9.8

CRITICAL

EPSS Score

50.5%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user input for the setup wizard, allowing an unauthenticated user to run arbitrary commands on the device. The vulnerability can be exercised on the local intranet or remotely if remote administration is enabled.

Technical details

Published
7/10/2019

Frequently asked questions

What is CVE-2019-13278?

TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user input for the setup wizard, allowing an unauthenticated user to run arbitrary commands on the device. The vulnerability can be exercised on the local intranet or remotely if remote administration is enabled.

Is CVE-2019-13278 actively exploited?

Active exploitation of CVE-2019-13278 has not been confirmed. The EPSS score is 50.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-13278?

CVE-2019-13278 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2019-13278 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.