Impact
The vulnerability is a command‑injection flaw in the log_email_server function of the /cgi-bin/email.cgi component of the TRENDnet TEW‑755AP router firmware. Manipulating input to that function lets an attacker issue arbitrary system commands, giving remote code execution capability. The flaw originates from insufficient input validation (CWE‑74) and the unsanitized use of user data in command execution (CWE‑77).
Affected Systems
Affecting TRENDnet TEW‑755AP routers carrying firmware up to 20260702, the log_email_server function is exposed through the router’s web‑management CGI interface, making the vulnerability reachable from any host that can access that interface, including external internet hosts.
Risk and Exploitability
With a CVSS score of 5.3, the flaw carries moderate severity, and no EPSS score is available while it is not listed in CISA’s KEV catalog. Nonetheless, a publicly available exploit and a remote attack vector mean that exposed routers could be compromised when attackers use the known exploitation code, raising the risk until a vendor patch is applied.
OpenCVE Enrichment