Vulnerability Description
A flaw has been found in TRENDnet TEW-821DAP 1.11B03. The impacted element is the function sub_43F2C4 of the file /goform/tools_nslookup of the component DNS Lookup Handler. This manipulation of the argument nslookup_target/dns_server causes os command injection. The attack can be initiated remotely. The vendor explains: "We are unable to confirm the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. " This vulnerability only affects products that are no longer supported by the maintainer.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Trendnet/TEW-821DAP_CI3.
- https://vuldb.com/cve/CVE-2026-15485
- https://vuldb.com/submit/842382
- https://vuldb.com/vuln/377792
- https://vuldb.com/vuln/377792/cti
FAQ
What is CVE-2026-15485?
CVE-2026-15485 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A flaw has been found in TRENDnet TEW-821DAP 1.11B03. The impacted element is the function sub_43F2C4 of the file /goform/tools_nslookup of the component DNS Lookup Handler. This manipulation of the a...
How severe is CVE-2026-15485?
CVE-2026-15485 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-15485?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.