CVE-2026-75984: TRENDnet TEW-823DRU admin.cgi command injection
Published Aug 19, 2026
·Updated
A vulnerability was detected in TRENDnet TEW-823DRU 1.1.02b01. Impacted is an unknown function of the file /cgi-bin/admin.cgi. The manipulation of the argument Hostname results in command injection. The attack can be launched remotely. The exploit is now public and may be used.
Affected Software
1 affected component
Trendnet TEW-823DRU=1.1.02b01
Event History
Aug 19, 2026
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must have low-level privileges. Exploitation is remote and does not require user interaction.
2
Which input is associated with the command injection?
The affected input is the Hostname argument handled by /cgi-bin/admin.cgi. Manipulating that argument can result in command injection.
3
Is public exploit code available?
Yes. The available data states that an exploit is public and may be used.