Impact
The flaw lies in the ping.cgi script of the TRENDnet TEW‑821DAP firmware. By manipulating the ipaddr parameter, an attacker can inject arbitrary system commands that are executed under the privileges of the web server. The vulnerability exemplifies command‑injection weaknesses, specifically CWE‑74 and CWE‑77, and enables full control over the device from a remote web request.
Affected Systems
Affected devices run the 2.2.01b05 firmware of the TRENDnet TEW‑821DAP router. The issue is identified by the vendor product TRENDnet:TEW‑821DAP. Any system using this firmware build is at risk; no other firmware versions have been reported as vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 marks the flaw as moderate. The publicly disclosed exploit demonstrates remote exploitation without authentication, indicating that attackers can trigger the injection over the internet. EPSS score of 1% indicates a low probability, but the existence of a public exploit and the references to its usage imply a meaningful risk. The vulnerability is not yet listed in CISA KEV, but its remote reach necessitates prompt action.
OpenCVE Enrichment