CVE-2026-5184: TRENDnet TEW-713RE setSysAdm command injection
A vulnerability was identified in TRENDnet TEW-713RE up to 1.02. The impacted element is an unknown function of the file /goform/setSysAdm. The manipulation of the argument admuser leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5184?
The CVE-2026-5184 vulnerability has a high severity level due to its potential for remote command injection.
How do I fix CVE-2026-5184?
To fix CVE-2026-5184, update the TRENDnet TEW-713RE firmware to the latest version that addresses this vulnerability.
What is the impact of CVE-2026-5184?
The impact of CVE-2026-5184 includes the possibility of unauthorized remote access and command execution on the device.
Who is affected by CVE-2026-5184?
Users of TRENDnet TEW-713RE routers with firmware version up to 1.02 are affected by CVE-2026-5184.
Is CVE-2026-5184 exploited in the wild?
Yes, CVE-2026-5184 is a command injection vulnerability that could be actively exploited by attackers if left unpatched.