Impact
The vulnerability resides in the firmware update handler of the TRENDnet TEW-821DAP router. The /goform/tools_ddns endpoint processes parameters hostname, username, or password and, via the subroutine sub_42026C, passes these values to the operating system without proper sanitization. This allows an attacker to inject arbitrary shell commands when accessing the remote management interface. The flaw is exploitable remotely and does not require local access.
Affected Systems
Only the TRENDnet TEW-821DAP router running firmware 1.11B03 is affected. The product line is end-of-life and the manufacturer has not issued a patch, leaving the device unsupported.
Risk and Exploitability
The CVSS rating of 5.3 indicates moderate severity, while an EPSS score of about 1 % signals a low real‑world exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Because it can be triggered remotely over the network, any attacker with access to the device’s management interface can execute arbitrary commands, but the lack of vendor support mitigates the risk of widespread attacks.
OpenCVE Enrichment