CVE 6.3 MEDIUM

TRENDnet TEW-821DAP Firmware Update new_gui_update_firmware data authenticity_CVE-2026-7606

6.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X

Description

A weakness has been identified in TRENDnet TEW-821DAP 1.12B01. This issue affects the function find_hwid/new_gui_update_firmware of the component Firmware Update Handler. Executing a manipulation of the argument dest can lead to insufficient verification of data authenticity. The attack can be launched remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The vendor explains: "That firmware version will only work on our hardware version v1.xR. We have already EOL that product 8 years ago and are no longer selling". This vulnerability only affects products that are no longer supported by the maintainer.

Basic Information

ID CVE-2026-7606
Source VulDB
Published May 2, 2026 at 06:45

Affected Product

Vendor TRENDnet
Product TEW-821DAP
Version 1.12B01
Affected Versions TRENDnet TEW-821DAP 1.12B01

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.