LiveActive security incident?Get immediate response
CVE Record

CVE-2021-33315: The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulner...

The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This vulnerability exists in its lldp related component. Due to lack of proper validation on length field of PortID TLV, by sending a crafted lldp packet to the device, integer underflow would occur and the negative number will be passed to memcpy() later, which may cause buffer overflow or invalid memory access.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2021-33315 affects TRENDnet TI-PG1284i hardware v2.0R switches before firmware 2.0.2.S0. A malformed LLDP network packet can trigger memory corruption behavior, potentially causing a crash or other unsafe device behavior. Public sources do not provide a CVSS score or confirmed exploitation.

Executive priority

Prioritize remediation for affected switches in sensitive production or operational networks. The business risk is device instability or memory corruption from local network traffic, but public evidence does not establish internet-scale exploitation or known active attacks.

Technical view

The vulnerability is an integer underflow in an LLDP-related component. Insufficient validation of the PortID TLV length can pass a negative value into memcpy(), which may lead to buffer overflow or invalid memory access. Evidence names TI-PG1284i hardware v2.0R before 2.0.2.S0.

Likely exposure

Exposure is most likely on networks using affected TRENDnet TI-PG1284i hardware v2.0R switches running firmware earlier than 2.0.2.S0. The attack path requires sending crafted LLDP traffic to the device, so practical exposure appears tied to local Layer 2 adjacency rather than internet reachability.

Exploitation context

The CVE source describes a crafted LLDP packet trigger. CISA KEV status is false in the supplied bundle, and no cited source confirms active exploitation or public weaponization. Treat exploitation evidence as incomplete.

Researcher notes

The public description gives root cause and trigger class but lacks CVSS, CWE, detailed impact boundaries, and exploit reliability. Avoid assuming remote internet exploitability; LLDP normally implies local link-layer reachability. Validate against actual hardware revision and firmware.

Mitigation direction

  • Inventory TRENDnet TI-PG1284i switches and confirm hardware revision.
  • Update affected hardware v2.0R devices to firmware 2.0.2.S0 or later.
  • Review TRENDnet support guidance before applying production firmware changes.
  • Limit untrusted Layer 2 access to switch-connected networks where practical.
  • Monitor affected switches for crashes or unexpected restarts.

Validation and detection

  • Check device model, hardware revision, and firmware version from management records.
  • Flag TI-PG1284i hw v2.0R devices below 2.0.2.S0 as affected.
  • Confirm whether LLDP is enabled or reachable on exposed switch ports.
  • Review logs for instability around LLDP-enabled interfaces.
  • Document compensating controls where firmware updates are delayed.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-33315 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.