Executive brief
A security vulnerability exists in the TRENDnet TEW-821DAP wireless access point, a device used to provide Wi-Fi connectivity in business environments. An attacker can exploit this flaw to cause a system crash or potentially take control of the device by sending a specially crafted network request. Because this product has reached its end-of-life status, the manufacturer is not providing security updates, leaving affected devices permanently exposed to this risk.
Technical details
A stack-based buffer overflow exists in the 'ssi' component of TRENDnet TEW-821DAP firmware version 1.12B01. The vulnerability is located in function sub_41EC14 within the /goform/tools_nslookup handler. The root cause is an insufficient buffer allocation (2 bytes) for a command string that is at least 33 bytes long ("nslookup ${host} > /tmp/nslookup"). An authenticated remote attacker can trigger this overflow by sending an HTTP POST request to the affected endpoint. Successful exploitation could lead to remote code execution (RCE) or a device crash. The vendor has stated the product is End-of-Life (EOL) and will not be patched.
Affected products
- TRENDnet TEW-821DAP 1.12B01
Timeline
- 2026-07-12: advisory: NVD publication date