Description
A vulnerability has been found in TRENDnet TEW-821DAP 1.11B03. This affects the function sub_42026C of the file /goform/tools_ddns of the component Firmware Update Handler. Such manipulation of the argument hostname/username/password leads to os command injection. The attack can be launched remotely. The vendor explains: "We are unable to confirm the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. " This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-07-12
Score: 5.3 Medium
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the firmware update handler of the TRENDnet TEW-821DAP router. The /goform/tools_ddns endpoint processes parameters hostname, username, or password and, via the subroutine sub_42026C, passes these values to the operating system without proper sanitization. This allows an attacker to inject arbitrary shell commands when accessing the remote management interface. The flaw is exploitable remotely and does not require local access.

Affected Systems

Only the TRENDnet TEW-821DAP router running firmware 1.11B03 is affected. The product line is end-of-life and the manufacturer has not issued a patch, leaving the device unsupported.

Risk and Exploitability

The CVSS rating of 5.3 indicates moderate severity, while an EPSS score of about 1 % signals a low real‑world exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Because it can be triggered remotely over the network, any attacker with access to the device’s management interface can execute arbitrary commands, but the lack of vendor support mitigates the risk of widespread attacks.

Generated by OpenCVE AI on July 31, 2026 at 12:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disconnect the TEW-821DAP unit from internal or public networks, or block its management interface at the firewall level to eliminate remote exposure.
  • If any community‑produced or custom firmware that removes the command‑injection flaw is available, validate it thoroughly and install it, ensuring that the tools_ddns routine performs proper input validation and sanitization.
  • Replace the unsupported device with a modern, supported model that receives regular security updates; if replacement is not immediately feasible, enforce strict network segmentation, limit management‑interface access to trusted sources, and disable all non‑essential services to reduce the attack surface.

Generated by OpenCVE AI on July 31, 2026 at 12:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 12 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Trendnet tew-821dap
Vendors & Products Trendnet tew-821dap

Sun, 12 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in TRENDnet TEW-821DAP 1.11B03. This affects the function sub_42026C of the file /goform/tools_ddns of the component Firmware Update Handler. Such manipulation of the argument hostname/username/password leads to os command injection. The attack can be launched remotely. The vendor explains: "We are unable to confirm the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. " This vulnerability only affects products that are no longer supported by the maintainer.
Title TRENDnet TEW-821DAP Firmware Update tools_ddns sub_42026C os command injection
First Time appeared Trendnet
Trendnet tew-821dap Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:trendnet:tew-821dap_firmware:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-821dap Firmware
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Trendnet Tew-821dap Tew-821dap Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-13T18:12:38.015Z

Reserved: 2026-07-11T10:12:24.075Z

Link: CVE-2026-15486

cve-icon Vulnrichment

Updated: 2026-07-13T18:02:17.383Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:45:03Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')