Executive brief
The TRENDnet TEW-823DRU is a network router used to provide wireless connectivity in homes and offices. A command injection vulnerability in its configuration interface allows an attacker to execute arbitrary system commands remotely, potentially taking full control of the device and using it as a foothold to attack connected networks or intercept user traffic.
Technical details
A command injection vulnerability exists in the nvram_get function of the CLI Configuration Tool component in TRENDnet TEW-823DRU firmware version 1.1.02b01. The vulnerability stems from insufficient input validation that allows an attacker to inject shell commands through the configuration interface. The attack is remotely exploitable and does not require prior authentication. An attacker can leverage this vulnerability to execute arbitrary commands with the privileges of the router's web server or administrative user, potentially gaining complete control over the device. Public exploits are available.
Affected products
- TRENDnet TEW-823DRU 1.1.02b01
Timeline
- 2026-08-22: disclosed