CVE-2026-7608

A vulnerability was detected in TRENDnet TEW-821DAP up to 1.12B01. The affected element is the function tools_diagnostic. The manipulation results in os command injection. The exploit is now public and may be used. The vendor explains: "That firmware version will only work on our hardware version v1.xR. We have already EOL that product 8 years ago and are no longer selling". This vulnerability only affects products that are no longer supported by the maintainer.
References
Link Resource
https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Trendnet/TEW-821DAP_CI1.md Exploit Third Party Advisory
https://vuldb.com/submit/806215 Third Party Advisory VDB Entry
https://vuldb.com/vuln/360565 Third Party Advisory VDB Entry
https://vuldb.com/vuln/360565/cti Permissions Required VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:trendnet:tew-821dap_firmware:1.12b01:*:*:*:*:*:*:*
cpe:2.3:h:trendnet:tew-821dap:1.0r:*:*:*:*:*:*:*

History

06 May 2026, 20:24

Type Values Removed Values Added
First Time Trendnet
Trendnet tew-821dap Firmware
Trendnet tew-821dap
CPE cpe:2.3:h:trendnet:tew-821dap:1.0r:*:*:*:*:*:*:*
cpe:2.3:o:trendnet:tew-821dap_firmware:1.12b01:*:*:*:*:*:*:*
References () https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Trendnet/TEW-821DAP_CI1.md - () https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Trendnet/TEW-821DAP_CI1.md - Exploit, Third Party Advisory
References () https://vuldb.com/submit/806215 - () https://vuldb.com/submit/806215 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/360565 - () https://vuldb.com/vuln/360565 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/360565/cti - () https://vuldb.com/vuln/360565/cti - Permissions Required, VDB Entry

02 May 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-02 09:16

Updated : 2026-05-06 20:24


NVD link : CVE-2026-7608

Mitre link : CVE-2026-7608

CVE.ORG link : CVE-2026-7608


JSON object : View

Products Affected

trendnet

  • tew-821dap_firmware
  • tew-821dap
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')