Impact
The vulnerability allows remote attackers to inject arbitrary operating‑system commands through the DNS Lookup Handler in TRENDnet TEW‑821DAP firmware. The flaw results from insufficient validation of the nslookup_target and dns_server parameters in the sub_43F2C4 function of /goform/tools_nslookup. Attackers can execute any command with the device’s privilege level, potentially compromising confidentiality, integrity, and enabling further network intrusion.
Affected Systems
The affected product is TRENDnet TEW‑821DAP model 1.11B03. The firmware is end‑of‑life and no longer maintained by the vendor. The flaw exists in the sub_43F2C4 function of the /goform/tools_nslookup component, and the vendor confirms that earlier unsupported firmware versions may also be affected.
Risk and Exploitability
The CVSS score of 5.3 denotes medium severity, while the EPSS score of 1% indicates a very low current exploitation probability. The flaw is remote and can be triggered via a crafted HTTP request to the /goform/tools_nslookup endpoint. If an attacker succeeds, they can run arbitrary OS commands on the device, gaining full control over the compromised appliance and potentially compromising the wider network.
OpenCVE Enrichment