Junglewise Threat Intelligence

CVE-2026-15486: TRENDnet TEW-821DAP OS command injection in tools_ddns

CVE-2026-15486 · Severity: medium · CVSS 6.3 · Published 2026-07-12

Technologies: TRENDnet TEW-821DAP. Vendors: TRENDnet.

Executive brief

A security vulnerability exists in the TRENDnet TEW-821DAP wireless access point, a device used to provide Wi-Fi connectivity in business and home environments. An attacker can remotely inject malicious commands into the device's configuration settings, potentially allowing them to take control of the hardware or disrupt network operations. Because this product has reached its end-of-life (EOL) status, the manufacturer will not be providing a security patch, leaving affected devices permanently vulnerable.

Technical details

An OS command injection vulnerability exists in the TRENDnet TEW-821DAP firmware version 1.11B03 within the 'ssi' program. The flaw is located in function sub_42026C, which handles DDNS configuration via the /goform/tools_ddns endpoint. The application fails to sanitize the 'hostname', 'username', and 'password' parameters before using sprintf to concatenate them into a configuration string. This string is subsequently written to a configuration file and executed via a system call to restart the DDNS service (/etc/init.d/ddns restart). An authenticated remote attacker can leverage this to execute arbitrary shell commands with the privileges of the web server. The vendor has stated the device is EOL and will not be patched.

Affected products

  • TRENDnet TEW-821DAP 1.11B03

Timeline

  • 2026-07-12: advisory: NVD publication date
  • 2026-07-12: disclosed: Public disclosure via VulDB and GitHub research repository

References

Related threats