Executive brief
A security vulnerability has been identified in the TRENDnet TEW-821DAP wireless access point. This device is used to provide Wi-Fi connectivity in business and home environments. An attacker could exploit this flaw to crash the device or potentially take full control of it, which could lead to unauthorized access to the network or interception of data. However, the manufacturer has stated that this product is at its End of Life (EOL) and will not receive a security patch.
Technical details
A stack-based buffer overflow exists in the 'ssi' component of TRENDnet TEW-821DAP firmware version 1.12B01. The vulnerability is located in function sub_41EC14 within the /goform/tools_nslookup handler. The root cause is an unsafe strcpy operation where the 'nslookup_target' environment variable (derived from user-supplied HTTP POST input) is copied into a fixed-size stack buffer without adequate bounds checking. An attacker providing an input greater than 392 bytes can overwrite the return address on the stack. This attack requires network reachability and low-privileged authentication. No patch is available as the vendor has designated the product as End of Life (EOL).
Affected products
- TRENDnet TEW-821DAP 1.12B01
Timeline
- 2026-07-12: advisory: NVD publication date