Junglewise Threat Intelligence

CVE-2026-15487: TRENDnet TEW-821DAP OS command injection in system_ntp

CVE-2026-15487 · Severity: medium · CVSS 6.3 · Published 2026-07-12

Technologies: TRENDnet TEW-821DAP. Vendors: TRENDnet.

Executive brief

A security vulnerability exists in the TRENDnet TEW-821DAP wireless access point, a device used to provide Wi-Fi connectivity in business environments. An attacker can exploit the device's time synchronization settings to execute unauthorized commands on the underlying operating system. This could allow a remote attacker to gain control over the device, potentially leading to network disruptions or unauthorized access to network traffic. Note that the manufacturer has designated this product as End-of-Life (EOL) and does not intend to release a fix.

Technical details

An OS command injection vulnerability exists in the TRENDnet TEW-821DAP firmware version 1.11B03 within the 'ssi' program. The vulnerability is located in function sub_41FBD0 (NTP handler) at the /goform/system_ntp endpoint. The 'Hostname' parameter provided via an HTTP POST request is concatenated into a shell command string using sprintf() and subsequently executed via system() without proper sanitization. An authenticated attacker can exploit this to execute arbitrary shell commands with the privileges of the web server. The vendor has stated the product is End-of-Life (EOL) and will not be patched.

Affected products

  • TRENDnet TEW-821DAP 1.11B03

Timeline

  • 2026-07-12: advisory: NVD publication date

References

Related threats