VYPR
patchPublished Aug 22, 2026· 1 source

Trendnet TEW-821DAP and TEW-823DRU Hit by Three Command Injection Flaws

Key findings • Critical command injection flaw (CVE-2026-77946) in TRENDnet TEW-821DAP with CVSS 10.0. • Two other command injection vulnerabilities (CVE-2026-77988, CVE-2026-77945) disclosed…

Key findings

  • Critical command injection flaw (CVE-2026-77946) in TRENDnet TEW-821DAP with CVSS 10.0.
  • Two other command injection vulnerabilities (CVE-2026-77988, CVE-2026-77945) disclosed for TRENDnet TEW-823DRU and TEW-821DAP.
  • Publicly available exploits exist for all three disclosed vulnerabilities.
  • Affected models include TRENDnet TEW-823DRU v1.1.02b01 and TEW-821DAP v2.2.01b05.
  • No patches are currently available; users advised to monitor Trendnet for updates.

On August 22, 2026, a batch of three vulnerabilities was disclosed for Trendnet devices, with a critical remote command injection flaw taking center stage. The vulnerabilities affect the TEW-823DRU and TEW-821DAP models, with the most severe issue in the TEW-821DAP allowing for complete system compromise.

Command Injection in TEW-821DAP

Two of the disclosed vulnerabilities, CVE-2026-77946 and CVE-2026-77945, impact the TRENDnet TEW-821DAP.

  • **CVE-2026-77946** is a critical command injection vulnerability within the NTP Timezone Configuration Handler. This flaw resides in the /cgi-bin/apply_time.cgi file and can be triggered by manipulating the system.ntp.server, system.ntp.enable_server, or cameo.time.time_zone arguments. The vulnerability has a CVSSv3 score of 10.0, indicating a critical severity.
  • **CVE-2026-77945**, also affecting the TEW-821DAP, is a high-severity command injection vulnerability. This flaw is located in the /cgi-bin/upload.cgi component and can be exploited by manipulating the filename argument. This vulnerability carries a CVSSv3 score of 7.4.

Both CVE-2026-77946 and CVE-2026-77945 have publicly available exploits, increasing the risk for unpatched devices.

Command Injection in TEW-823DRU

The third vulnerability, **CVE-2026-77988**, affects the TRENDnet TEW-823DRU. This medium-severity flaw (CVSSv3 6.6) is a command injection vulnerability within the CLI Configuration Tool, specifically impacting the nvram_get function. While remotely exploitable, the description indicates it is less severe than the issues found in the TEW-821DAP. An exploit for this vulnerability has also been made public.

Affected Products and Patch Status

The disclosed vulnerabilities affect the following Trendnet devices:

  • TRENDnet TEW-823DRU running firmware version 1.1.02b01.
  • TRENDnet TEW-821DAP running firmware version 2.2.01b05.

Trendnet has not yet released specific patches for these vulnerabilities. Users are advised to monitor the Trendnet support website for firmware updates. Given the public availability of exploits for all three CVEs, immediate mitigation and patching are strongly recommended.

These vulnerabilities highlight the ongoing risks associated with network device security. Users of Trendnet devices should prioritize updating their firmware as soon as patches become available and implement network segmentation and access controls to limit the potential impact of any successful exploitation. The presence of multiple command injection flaws across different devices underscores the importance of regular security audits and timely patching for all network infrastructure.

Synthesized by Vypr AI