Skip to main content
CRITICAL

CVE-2019-13278

CVSS v3

9.8

CRITICAL

EPSS Score

8.8 %

exploit probability, as of 2026-10-05

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user input for the setup wizard, allowing an unauthenticated user to run arbitrary commands on the device. The vulnerability can be exercised on the local intranet or remotely if remote administration is enabled.

Technical details

Published
2019-07-10

Frequently asked questions

What is CVE-2019-13278?

TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user input for the setup wizard, allowing an unauthenticated user to run arbitrary commands on the device. The vulnerability can be exercised on the local intranet or remotely if remote administration is enabled.

Is CVE-2019-13278 actively exploited?

Active exploitation of CVE-2019-13278 has not been confirmed. Its EPSS score was 8.8% on 2026-10-05, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-13278?

CVE-2019-13278 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2019-13278 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key