.. / CVE-2021-20150

Exploit for Trendnet AC2600 TEW-827DRU - Credentials Disclosure (CVE-2021-20150)

Description:

Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. A user may view information as Admin by manually browsing to the setup wizard and forcing it to redirect to the desired page.

Nuclei Template

View the template here CVE-2021-20150.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-20150.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2021-20150
https://www.tenable.com/security/research/tra-2021-54