Description
A vulnerability was detected in TRENDnet TEW-823DRU 1.1.02b01. Impacted is an unknown function of the file /cgi-bin/admin.cgi. The manipulation of the argument Hostname results in command injection. The attack can be launched remotely. The exploit is now public and may be used.
Published: 2026-08-19
Score: 5.3 Medium
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the admin.cgi handler of the TRENDnet TEW‑823DRU firmware 1.1.02b01. A crafted Hostname parameter is interpreted by the router’s web interface, leading to system‑level command execution. This flaw represents a command‑injection weakness (CWE‑74) due to insufficient input validation, and, based on the absence of authentication, also indicates an improper access‑control weakness (CWE‑77). An attacker who can reach the device’s web server can run arbitrary commands remotely, without needing authentication, and the exploit is publicly available.

Affected Systems

Affected devices are TRENDnet TEW‑823DRU wireless routers running firmware version 1.1.02b01. No other models or firmware revisions are reported. Devices may be deployed in home or small‑office networks.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, but the public nature of the exploit and the fact that it can be triggered from any remote host raise real operational risk. The EPSS score is 0.01293, indicating a low but measurable exploitation probability. The issue is not listed in the CISA KEV catalog, yet the ability to execute arbitrary commands on a network gateway can lead to network compromise, malware deployment, or denial of service.

Generated by OpenCVE AI on August 20, 2026 at 18:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest TEW‑823DRU firmware that removes the vulnerable admin.cgi code.
  • If a firmware update is unavailable, block or disable the /cgi-bin/admin.cgi endpoint from external access, for example by restricting the router’s web management to the LAN or a dedicated VLAN.
  • Configure firewall or router ACLs to allow web interface traffic only from trusted internal addresses, preventing external remote connections to the router’s administrative interface.

Generated by OpenCVE AI on August 20, 2026 at 18:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in TRENDnet TEW-823DRU 1.1.02b01. Impacted is an unknown function of the file /cgi-bin/admin.cgi. The manipulation of the argument Hostname results in command injection. The attack can be launched remotely. The exploit is now public and may be used.
Title TRENDnet TEW-823DRU admin.cgi command injection
First Time appeared Trendnet
Trendnet tew-823dru
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:trendnet:tew-823dru:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-823dru
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


Subscriptions

Trendnet Tew-823dru
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-19T13:43:50.638Z

Reserved: 2026-08-18T18:27:17.455Z

Link: CVE-2026-75984

cve-icon Vulnrichment

Updated: 2026-08-19T13:43:47.974Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T01:16:57.640

Modified: 2026-08-20T12:48:31.843

Link: CVE-2026-75984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T18:30:04Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')