Vulnerability Description
A vulnerability has been found in TRENDnet TEW-821DAP 1.11B03. This affects the function sub_42026C of the file /goform/tools_ddns of the component Firmware Update Handler. Such manipulation of the argument hostname/username/password leads to os command injection. The attack can be launched remotely. The vendor explains: "We are unable to confirm the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. " This vulnerability only affects products that are no longer supported by the maintainer.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Trendnet/TEW-821DAP_CI4.
- https://vuldb.com/cve/CVE-2026-15486
- https://vuldb.com/submit/842383
- https://vuldb.com/vuln/377793
- https://vuldb.com/vuln/377793/cti
FAQ
What is CVE-2026-15486?
CVE-2026-15486 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability has been found in TRENDnet TEW-821DAP 1.11B03. This affects the function sub_42026C of the file /goform/tools_ddns of the component Firmware Update Handler. Such manipulation of the ar...
How severe is CVE-2026-15486?
CVE-2026-15486 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-15486?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.