Vulnerability Description
A vulnerability was found in TRENDnet TEW-821DAP 1.11B03. This impacts the function sub_41FBD0 of the file /goform/system_ntp of the component Firmware Update Handler. Performing a manipulation of the argument Hostname results in os command injection. The attack may be initiated remotely. The vendor explains: "We are unable to confirm the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. " This vulnerability only affects products that are no longer supported by the maintainer.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Trendnet/TEW-821DAP_CI5.
- https://vuldb.com/cve/CVE-2026-15487
- https://vuldb.com/submit/842385
- https://vuldb.com/vuln/377794
- https://vuldb.com/vuln/377794/cti
FAQ
What is CVE-2026-15487?
CVE-2026-15487 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability was found in TRENDnet TEW-821DAP 1.11B03. This impacts the function sub_41FBD0 of the file /goform/system_ntp of the component Firmware Update Handler. Performing a manipulation of the...
How severe is CVE-2026-15487?
CVE-2026-15487 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-15487?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.