Description
A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. This vulnerability affects the function nvram_get of the component CLI Configuration Tool. This manipulation causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-08-22
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The TEW-823DRU firmware version 1.1.02b01 contains a command injection flaw in the nvram_get function of the CLI Configuration Tool. The flaw is a classic input validation failure that allows an attacker to inject arbitrary shell commands through crafted input strings, resulting in remote execution of commands on the device. Since the CLI tool is exposed over the network, the vulnerability permits attackers to compromise the system without needing local access.

Affected Systems

Affected devices are TRENDnet TEW-823DRU routers running firmware 1.1.02b01. No patched versions have been identified in the supplied data; vendors should verify if a newer build incorporates the fix. The vulnerability is specific to the TEW-823DRU model, as indicated by the CPE entry.

Risk and Exploitability

The CVSS score is 5.1, classifying it as medium severity, while the EPSS score is unavailable and it has not been listed in CISA’s KEV catalog. However, public proof‑of‑concept exploits are available, showing that the attack is feasible remotely. Attackers can exploit the vulnerability by sending specially crafted requests to the CLI interface, potentially gaining arbitrary command execution and full control over the device.

Generated by OpenCVE AI on August 22, 2026 at 13:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to the latest stable release that addresses the nvram_get command injection vulnerability.
  • If an updated firmware is not yet available, restrict external access to the CLI tool by firewalling or disabling the public interface so only trusted, local network users can reach it.
  • Enable logging of CLI access and monitor logs for anomalous nvram_get calls; consider stricter input validation if firmware or configuration can be modified.

Generated by OpenCVE AI on August 22, 2026 at 13:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. This vulnerability affects the function nvram_get of the component CLI Configuration Tool. This manipulation causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Title TRENDnet TEW-823DRU CLI Configuration Tool nvram_get command injection
First Time appeared Trendnet
Trendnet tew-823dru
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:trendnet:tew-823dru:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-823dru
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.6, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


Subscriptions

Trendnet Tew-823dru
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-22T11:45:09.743Z

Reserved: 2026-08-21T18:54:59.116Z

Link: CVE-2026-77988

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-22T12:16:25.817

Modified: 2026-08-22T12:16:25.817

Link: CVE-2026-77988

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T13:45:03Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')