← Vulnerability feed

Vulnerability record · CVE-2026-7609 · published 2 May 2026

CVE-2026-7609: Trendnet tew-821dap firmware command injection vulnerability

Trendnet · Tew 821dap Firmware

A flaw has been found in TRENDnet TEW-821DAP up to 1.12B01. The impacted element is the function tools_diagnostic of the file /tmp/diagnostic of the component Firmware Udpate. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor explains: "That firmware version will only work on our hardware version v1.xR. We have already EOL that product 8 years ago and are no longer selling". This vulnerability only affects products that are no longer supported by the maintainer.

2.1 CVSS 4.0 Low EPSS 5.7% · top 7.2% CWE-77 · Command injectionCWE-78 · OS command injection
2.1CVSS 4.0 base score, v2 6.5
5.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A flaw has been found in TRENDnet TEW-821DAP up to 1.12B01. The impacted element is the function tools_diagnostic of the file /tmp/diagnostic of the component Firmware Udpate. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor explains: "That firmware version will only work on our hardware version v1.xR. We have already EOL that product 8 years ago and are no longer selling". This vulnerability only affects products that are no longer supported by the maintainer.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Trendnet/TEW-821DAP_CI2.md ExploitThird Party Advisory
https://vuldb.com/submit/806216 Third Party AdvisoryVDB Entry
https://vuldb.com/vuln/360566 Third Party AdvisoryVDB Entry
https://vuldb.com/vuln/360566/cti Permissions RequiredVDB Entry

Track CVE-2026-7609 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2026-7607Trendnet tew-821dap firmware memory buffer overflow vulnerabilityA security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function auto_update_firmware of the component Firmware Ud…EPSS 1.0%8.0CVE-2023-51146Trendnet tew-821dap firmware stack-based buffer overflow vulnerabilityBuffer Overflow vulnerability in TRENDnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_ad…EPSS 0.50%8.0CVE-2023-51147Trendnet tew-821dap firmware stack-based buffer overflow vulnerabilityBuffer Overflow vulnerability in TRENDnet Trendnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via t…EPSS 0.50%8.0CVE-2023-51148Trendnet tew-821dap firmware stack-based buffer overflow vulnerabilityAn issue in TRENDnet Trendnet AC1200 Dual Band PoE Indoor Wireless Access Point TEW-821DAP v.3.00b06 allows an attacker to execute arbitrary code via…EPSS 0.53%6.3CVE-2026-7611Trendnet tew-821dap firmware insufficient verification of data authenticity vulnerabilityA vulnerability was found in TRENDnet TEW-821DAP up to 1.12B01. This impacts the function platform_do_upgrade_cameo_dev of the file cameo_dev.sh of t…EPSS 0.31%6.3CVE-2026-7606Trendnet tew-821dap firmware insufficient verification of data authenticity vulnerabilityA weakness has been identified in TRENDnet TEW-821DAP 1.12B01. This issue affects the function find_hwid/new_gui_update_firmware of the component Fir…EPSS 0.31%2.9CVE-2026-7610Trendnet tew-821dap firmware cleartext transmission vulnerabilityA vulnerability has been found in TRENDnet TEW-821DAP 1.12B01. This affects an unknown function of the file /www/cgi/ssi of the component Firmware Up…EPSS 0.45%2.0CVE-2026-7608Trendnet tew-821dap firmware command injection vulnerabilityA vulnerability was detected in TRENDnet TEW-821DAP up to 1.12B01. The affected element is the function tools_diagnostic. The manipulation results in…EPSS 9.8%

Source: NIST National Vulnerability Database (record CVE-2026-7609), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.