CVE-2026-15486: TRENDnet TEW-821DAP Firmware Update tools_ddns sub_42026C os command injection
A vulnerability has been found in TRENDnet TEW-821DAP 1.11B03. This affects the function sub42026C of the file /goform/toolsddns of the component Firmware Update Handler. Such manipulation of the argument hostname/username/password leads to os command injection. The attack can be launched remotely. The vendor explains: "We are unable to confirm the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. " This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15486?
The severity of CVE-2026-15486 is rated medium with a score of 6.3.
What type of vulnerability is CVE-2026-15486?
CVE-2026-15486 is an OS command injection vulnerability found in the TRENDnet TEW-821DAP firmware.
How does CVE-2026-15486 affect the TRENDnet TEW-821DAP?
CVE-2026-15486 allows remote attackers to execute arbitrary commands on the device through manipulation of the hostname/username/password parameters.
Can CVE-2026-15486 be exploited remotely?
Yes, CVE-2026-15486 can be exploited remotely due to the nature of the vulnerability.
How do I fix CVE-2026-15486?
To mitigate CVE-2026-15486, users should update their TRENDnet TEW-821DAP firmware to the latest version provided by the vendor.