Executive brief
A security vulnerability has been identified in the TRENDnet TEW-821DAP wireless access point, a device used to provide Wi-Fi connectivity in business environments. An attacker could exploit this flaw to take control of the device by injecting malicious commands through the network diagnostic tools. Because this product has reached its end-of-life status, the manufacturer will not be providing a security patch, leaving affected devices permanently vulnerable.
Technical details
An OS command injection vulnerability exists in the TRENDnet TEW-821DAP firmware version 1.11B03 within the 'ssi' binary. The flaw is located in function sub_43F2C4, which handles DNS lookup requests via the /goform/tools_nslookup endpoint. The application fails to sanitize the 'nslookup_target' and 'dns_server' POST parameters before passing them to a sprintf call that constructs a system command (e.g., "nslookup %s %s"). An authenticated attacker can inject shell metacharacters into these parameters to execute arbitrary code with the privileges of the web server. The vendor has stated the product is End-of-Life (EOL) and will not be patched.
Affected products
- TRENDnet TEW-821DAP 1.11B03
Timeline
- 2026-07-12: advisory: NVD publication date
- 2026-07-12: disclosed: Initial disclosure via VulDB and GitHub research report