CVE-2021-20151
CVE-2021-20151
10.0
CriticalPublished:
Last updated:
Source:vulnreport@tenable.com
Modified
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Description
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's management software manages web sessions based on IP address rather than verifying client cookies/session tokens/etc. This allows an attacker (whether from a different computer, different web browser on the same machine, etc.) to take over an existing session. This does require the attacker to be able to spoof or take over original IP address of the original user's session.
References
vulnreport@tenable.com
https://www.tenable.com/security/research/tra-2021-54af854a3a-2127-422b-91ae-364da2661108
https://www.tenable.com/security/research/tra-2021-54