CVE-2026-75985: TRENDnet Router ping.cgi command injection
Published Aug 19, 2026
·Updated
A flaw has been found in TRENDnet Router 1.1.02b01. The affected element is an unknown function of the file /cgi-bin/ping.cgi. This manipulation of the argument wantype causes command injection. The attack may be initiated remotely. The exploit has been published and may be used.
Affected Software
1 affected component
Trendnet TRENDnet Router=1.1.02b01
Event History
Aug 19, 2026
CVE Published
via MITRE·01:15 AM
Data Sourced
via MITRE·01:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attack can be initiated remotely and requires low privileges. No user interaction is required.
2
Which component and input are implicated?
The issue affects an unknown function in /cgi-bin/ping.cgi. It is triggered by manipulating the wan_type argument, leading to command injection.
3
Is exploit code available?
Yes. An exploit has been published and may be used.