PT-2018-17862 · Trendnet · Trendnet Tew733Gr+2

CVE-2018-7034

·

Published

2018-02-14

·

Updated

2022-12-12

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TRENDnet TEW-751DR version 1.03B03 TRENDnet TEW-752DRU version 1.03B01 TRENDnet TEW-733GR version 1.03B01
Description The issue allows authentication bypass via an AUTHORIZED GROUP=1 value. This can be demonstrated by sending a request for "getcfg.php", which is an API endpoint, allowing unauthorized access.
Recommendations For TRENDnet TEW-751DR version 1.03B03, consider disabling access to the "getcfg.php" endpoint until a fix is available. For TRENDnet TEW-752DRU version 1.03B01, restrict the use of the AUTHORIZED GROUP variable to prevent unauthorized access. For TRENDnet TEW-733GR version 1.03B01, avoid using the AUTHORIZED GROUP=1 value in requests to the "getcfg.php" endpoint to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-7034

Affected Products

Trendnet Tew733Gr
Trendnet Tew-751Dr
Trendnet Tew-752Dru