CVE-2026-19841
Received Received - Intake

Incorrect Default Permissions in TRENDNET TEW-813DRU

Vulnerability report for CVE-2026-19841, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-14

Last updated on: 2026-08-14

Assigner: VulDB

Description

A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes incorrect default permissions. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitability is considered difficult. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-14
Last Modified
2026-08-14
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
trendnet tew-813dru 1.01b01

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
CWE-276 During installation, installed file permissions are set to allow anyone to modify those files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-19841 is a flaw in TRENDNET TEW-813DRU version 1.01b01 where an unknown function in the vsftpd component's /etc/vsftpd.conf file leads to incorrect default permissions. The issue allows remote attackers to manipulate settings, though the attack requires high complexity and is considered difficult to exploit. The vulnerability only affects unsupported products.

Detection Guidance

Since this vulnerability affects the TRENDNET TEW-813DRU router with outdated firmware and vsftpd configuration, check if the device is still in use and running the vulnerable version. Inspect /etc/vsftpd.conf for incorrect default permissions on the file. Use commands like 'cat /etc/vsftpd.conf' or 'ls -l /etc/vsftpd.conf' to verify permissions.

Impact Analysis

This vulnerability could allow unauthorized remote access or modification of system permissions on affected devices. However, exploitation is difficult due to high complexity, and the product is no longer supported, reducing real-world risk. Impact is limited to specific TRENDNET TEW-813DRU devices running the vulnerable firmware.

Mitigation Strategies

Immediately update the router firmware to the latest supported version or replace the device if it is no longer supported. Remove or secure the vsftpd service if unused. Ensure proper file permissions are set on /etc/vsftpd.conf to prevent unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19841. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart