LiveActive security incident?Get immediate response
CVE Record

CVE-2021-33316: The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulner...

The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This vulnerability exists in its lldp related component. Due to lack of proper validation on length field of ChassisID TLV, by sending a crafted lldp packet to the device, integer underflow would occur and the negative number will be passed to memcpy() later, which may cause buffer overflow or invalid memory access.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2021-33316 affects TRENDnet TI-PG1284i switch hardware v2.0R before firmware 2.0.2.S0. A malformed LLDP network packet can trigger memory corruption or invalid memory access. The available sources do not provide a CVSS score, confirmed real-world exploitation, or detailed vendor mitigation text beyond the version boundary.

Executive priority

Treat this as a targeted infrastructure hygiene issue. Prioritize affected switches in operational or exposed network segments, but avoid emergency framing unless internal exposure is broad or vendor evidence of exploitation emerges.

Technical view

The flaw is an integer underflow in the switch LLDP component. Insufficient validation of the ChassisID TLV length field can pass a negative value into memcpy(), potentially causing buffer overflow or invalid memory access when a crafted LLDP packet is received.

Likely exposure

Exposure is limited to TRENDnet TI-PG1284i hardware v2.0R devices running firmware earlier than 2.0.2.S0. Practical reach appears network-adjacent because LLDP operates at Layer 2, but the sources do not state authentication, interface scope, or default LLDP settings.

Exploitation context

The CVE record describes exploitation by a crafted LLDP packet. CISA KEV status is false in the supplied bundle, and no cited source confirms active exploitation or public weaponization.

Researcher notes

Evidence is sparse: no CVSS vector, CWE, exploit status, or detailed advisory text is included. The core risk is source-grounded memory corruption from malformed LLDP ChassisID TLV length handling on the named switch and firmware range.

Mitigation direction

  • Identify all TRENDnet TI-PG1284i hardware v2.0R switches.
  • Check firmware and prioritize upgrades to 2.0.2.S0 or later.
  • Review TRENDnet support guidance for applicable firmware and release notes.
  • Limit untrusted Layer 2 access to switch ports where feasible.
  • Monitor for crashes or unusual LLDP-related behavior.

Validation and detection

  • Confirm model, hardware revision, and firmware version from device inventory.
  • Verify whether any device runs firmware earlier than 2.0.2.S0.
  • Check whether LLDP is enabled and reachable on exposed ports.
  • Review logs for unexpected reboots or LLDP parsing errors.
  • Document compensating controls for devices awaiting firmware updates.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-33316 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.