Sceawere
Vulnerability Detail
CVE-2026-19830UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
TRENDnet TEW-816DRM bftpd Resource Allocation Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 2h ago
- Vendor
- TRENDnet
- Product
- TEW-816DRM
- Attack Type
- Allocation of Resources
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of the file /etc/bftpd.conf of the component bftpd. The manipulation of the argument USERLIMIT_GLOBAL results in allocation of resources. It is possible to launch the attack remotely. This vulnerability only affects products that are no longer supported by the maintainer.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-08-14T14:16:51.317Z",
"pubdate": "2026-08-14T14:16:51.317Z",
"executiveSummary": "A resource allocation vulnerability exists within the bftpd component of the TRENDnet TEW-816DRM router running firmware version GURNC4.OT182B-C-TN-R1B028-US.EN. Specifically, the flaw resides in the handling of the USERLIMIT_GLOBAL argument within the configuration file /etc/bftpd.conf.\nThis vulnerability allows remote attackers to manipulate global user limits, leading to improper resource allocation on the targeted device. Exploitation of this flaw can result in resource exhaustion and subsequent denial of service conditions, severely impacting device availability.\nThe affected product is obsolete and no longer supported by the vendor, meaning official security updates or patches will not be released. Consequently, the risk profile for deployments utilizing this firmware remains permanently elevated. Attackers can leverage network-based access to interact with the vulnerable File Transfer Protocol daemon without requiring prior authentication, depending on service exposure configurations.\nMitigation options are strictly limited due to the end-of-life status of the hardware and software, necessitating network segmentation, service disablement, or complete device replacement to eliminate the exposure.",
"technicalDetails": "The vulnerability is rooted in insecure configuration parsing and resource management within the bftpd service running on the TRENDnet TEW-816DRM router. The vulnerable component is the bftpd daemon, specifically how it processes parameters defined in the configuration file located at /etc/bftpd.conf.\nThe root cause stems from the application's failure to adequately validate and sanitize input supplied to the USERLIMIT_GLOBAL parameter. When an unauthenticated remote attacker sends maliciously crafted instructions or modifies configuration states that interact with this parameter, the application attempts to allocate system memory or processing resources based on the untrusted input without enforcing strict upper bounds or validation checks.\nThe attack flow proceeds as follows: First, the remote adversary establishes network connectivity to the listening bftpd service on the target device. Second, the attacker interacts with the service or manipulates the USERLIMIT_GLOBAL configuration context. Third, upon parsing the manipulated argument, the bftpd process initiates an uncontrolled resource allocation sequence. This improper handling forces the underlying operating system to commit excessive memory or handle anomalous connection thresholds.\nThe primary impact of this exploitation vector is resource exhaustion, which can lead to service crashes, instability, or a complete denial of service (DoS) for legitimate users attempting to utilize the FTP service or router management interfaces. Because the affected firmware version GURNC4.OT182B-C-TN-R1B028-US.EN lacks modern defensive programming safeguards against resource exhaustion and is part of a discontinued product line, the system cannot recover gracefully from such malformed allocations."
}