Impact
A remote attacker can exploit a flaw in the Firmware Update Handler of the TRENDnet TEW-821DAP, specifically the sub_41FBD0 function in /goform/system_ntp. By manipulating the Hostname parameter, an attacker can inject arbitrary operating‑system commands, potentially leading to full system compromise, data exfiltration, or persistence. The weakness aligns with CWE-77 and CWE-78, indicating untrusted input is passed to an OS command execution routine.
Affected Systems
The vulnerability affects the TRENDnet TEW-821DAP model running firmware version 1.11B03, a build that has been marked end‑of‑life and is no longer supported by the vendor. No other versions are explicitly listed, but the issue is limited to this firmware release and possibly earlier unsupported builds.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. The EPSS score of 1% suggests a low exploitation probability at present; however, it is not zero and could become more attractive over time. The vulnerability is not catalogued in CISA KEV, and there is no known public exploit. Attackers would need to reach the device over the network to send a crafted HTTP request that triggers the vulnerable function, which implies a remote attack vector. Given the lack of an official remediation, the risk is primarily mitigated by stopping use or through manual defensive controls.
OpenCVE Enrichment