← Back to browse · API

CVE-2024-28354

Severity
CRITICAL
CVSS
10.0
EPSS
0.02218
Risk score
40.78
CISA KEV
No
PoC
No
Published
2024-03-15
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2024-25452, GHSA-X655-QHF6-RJFW
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-25452

Description

There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.@smb[%d].username in the apply.cgi interface, thereby gaining root shell privileges.

References