CVE-2026-15487: TRENDnet Tew-821dap
Medium severity, CVSS 6.3. EPSS: 1.8% chance of exploitation in the next 30 days.
A vulnerability was found in TRENDnet TEW-821DAP 1.11B03. This impacts the function sub_41FBD0 of the file /goform/system_ntp of the component Firmware Update Handler. Performing a manipulation of the argument Hostname results in os command injection. The attack may be initiated remotely. The vendor explains: "We are unable to confirm the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. " This vulnerability only affects products that are no longer supported by the maintainer.
Affected products
- TRENDnet Tew-821dap: version 1.11B03 only
Published 2026-07-12. Last modified 2026-07-13.