Sceawere
Vulnerability Detail
CVE-2026-19841UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
TRENDNET TEW-813DRU Incorrect Default Permissions
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.1
- Creation Date
- 1h ago
- Vendor
- TRENDNET
- Product
- TEW-813DRU
- Attack Type
- Incorrect Default Permissions
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes incorrect default permissions. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitability is considered difficult. This vulnerability only affects products that are no longer supported by the maintainer.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.1",
"pubDate": "2026-08-14T17:17:34.993Z",
"pubdate": "2026-08-14T17:17:34.993Z",
"executiveSummary": "A security flaw involving incorrect default permissions has been identified in the TRENDNET TEW-813DRU router running firmware version 1.01b01. The vulnerability specifically affects an unknown function within the /etc/vsftpd.conf configuration file of the vsftpd component. This misconfiguration leads to improper permission assignments, which can potentially be manipulated by a remote threat actor.\nThe risk implications of this vulnerability are tied to unauthorized access or modification of sensitive system configurations managed by the File Transfer Protocol daemon. However, successful exploitation of this flaw requires a high degree of complexity and is considered difficult to execute in practice.\nCrucially, the affected product is past its end-of-life lifecycle and is no longer supported by the vendor or maintainer, meaning official patches or vendor-supplied firmware updates will not be made available to remediate the underlying issue. Consequently, organizations utilizing this device face residual risks unless compensatory security controls or network isolation measures are implemented.",
"technicalDetails": "The vulnerability resides within the vsftpd component of the TRENDNET TEW-813DRU running firmware version 1.01b01, specifically concerning the handling and configuration of the /etc/vsftpd.conf file. The root cause stems from the implementation of incorrect default permissions assigned to sensitive configuration or operational files associated with the File Transfer Protocol daemon.\nFrom a network exposure perspective, the attack vector is accessible remotely, meaning an adversary interacts with network-facing services or interfaces that parse, expose, or interact with the misconfigured vsftpd component. The vulnerability requires a high degree of complexity to exploit, indicating that standard automated attack tools will likely fail and that successful exploitation demands intricate manipulation of the target environment.\nThe attack flow involves leveraging the weak permission model governing the vulnerable component to compromise the integrity or confidentiality of the affected file path. Because default permissions are improperly configured, unauthorized entities may be positioned to read or manipulate parameters defined within /etc/vsftpd.conf. This configuration file dictates the operational boundaries, user access controls, and security constraints of the vsftpd service.\nAlthough specific authentication and privilege requirements are dictated by the remote nature of the interface and the overarching system architecture, the flaw inherently bypasses intended access restrictions due to the weak default permission state. The post-exploitation impact centers around potential unauthorized access to the underlying filesystem, modification of FTP daemon behaviors, or exposure of sensitive credentials and system data handled by the vsftpd service. Given that the affected product and version are no longer supported by the maintainer, internal defensive hardening remains the only viable path to mitigate systemic exposure."
}