Description
A flaw has been found in TRENDnet TEW-821DAP 1.11B03. The impacted element is the function sub_43F2C4 of the file /goform/tools_nslookup of the component DNS Lookup Handler. This manipulation of the argument nslookup_target/dns_server causes os command injection. The attack can be initiated remotely. The vendor explains: "We are unable to confirm the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. " This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-07-12
Score: 5.3 Medium
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows remote attackers to inject arbitrary operating‑system commands through the DNS Lookup Handler in TRENDnet TEW‑821DAP firmware. The flaw results from insufficient validation of the nslookup_target and dns_server parameters in the sub_43F2C4 function of /goform/tools_nslookup. Attackers can execute any command with the device’s privilege level, potentially compromising confidentiality, integrity, and enabling further network intrusion.

Affected Systems

The affected product is TRENDnet TEW‑821DAP model 1.11B03. The firmware is end‑of‑life and no longer maintained by the vendor. The flaw exists in the sub_43F2C4 function of the /goform/tools_nslookup component, and the vendor confirms that earlier unsupported firmware versions may also be affected.

Risk and Exploitability

The CVSS score of 5.3 denotes medium severity, while the EPSS score of 1% indicates a very low current exploitation probability. The flaw is remote and can be triggered via a crafted HTTP request to the /goform/tools_nslookup endpoint. If an attacker succeeds, they can run arbitrary OS commands on the device, gaining full control over the compromised appliance and potentially compromising the wider network.

Generated by OpenCVE AI on July 29, 2026 at 08:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Replace the TEW‑821DAP device with a TRENDnet model that is still supported and actively maintained.
  • Block the /goform/tools_nslookup endpoint at the network perimeter or disable the DNS lookup feature via access control lists.
  • Isolate the device behind a strict firewall rule set that limits inbound exposure to only trusted management hosts.

Generated by OpenCVE AI on July 29, 2026 at 08:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 12 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Trendnet tew-821dap
Vendors & Products Trendnet tew-821dap

Sun, 12 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in TRENDnet TEW-821DAP 1.11B03. The impacted element is the function sub_43F2C4 of the file /goform/tools_nslookup of the component DNS Lookup Handler. This manipulation of the argument nslookup_target/dns_server causes os command injection. The attack can be initiated remotely. The vendor explains: "We are unable to confirm the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. " This vulnerability only affects products that are no longer supported by the maintainer.
Title TRENDnet TEW-821DAP DNS Lookup tools_nslookup sub_43F2C4 os command injection
First Time appeared Trendnet
Trendnet tew-821dap Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:trendnet:tew-821dap_firmware:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-821dap Firmware
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Trendnet Tew-821dap Tew-821dap Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-14T14:40:25.911Z

Reserved: 2026-07-11T10:12:21.398Z

Link: CVE-2026-15485

cve-icon Vulnrichment

Updated: 2026-07-14T14:40:20.505Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T09:00:18Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')