Impact
A buffer overflow exists in the sub_41EC14 function of the /goform/tools_nslookup component. Manipulating the nslookup_target argument can overflow a buffer, a flaw that can be triggered remotely through the web interface. Although the description does not confirm arbitrary code execution, a buffer overflow could corrupt memory, potentially enabling denial of service or remote code execution on the device.
Affected Systems
TRENDnet TEW‑821DAP model 1.12B01 is affected. The firmware version 1.12B01 is no longer supported by the vendor, and no current production firmware address this issue.
Risk and Exploitability
The CVSS score of 8.7 signals high severity. The EPSS score is below 1%, indicating a low probability of public exploitation today, and the vulnerability is not listed in the CISA KEV catalog. Because the affected firmware is EOL yet may still be deployed, devices remain susceptible to a remote attacker sending a crafted nslookup_target string via the web interface, which could lead to device compromise.
OpenCVE Enrichment