Impact
The vulnerability resides in the admin.cgi handler of the TRENDnet TEW‑823DRU firmware 1.1.02b01. A crafted Hostname parameter is interpreted by the router’s web interface, leading to system‑level command execution. This flaw represents a command‑injection weakness (CWE‑74) due to insufficient input validation, and, based on the absence of authentication, also indicates an improper access‑control weakness (CWE‑77). An attacker who can reach the device’s web server can run arbitrary commands remotely, without needing authentication, and the exploit is publicly available.
Affected Systems
Affected devices are TRENDnet TEW‑823DRU wireless routers running firmware version 1.1.02b01. No other models or firmware revisions are reported. Devices may be deployed in home or small‑office networks.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, but the public nature of the exploit and the fact that it can be triggered from any remote host raise real operational risk. The EPSS score is 0.01293, indicating a low but measurable exploitation probability. The issue is not listed in the CISA KEV catalog, yet the ability to execute arbitrary commands on a network gateway can lead to network compromise, malware deployment, or denial of service.
OpenCVE Enrichment