CVE-2026-76582: TRENDnet TEW-821DAP ssi ping.cgi system command injection
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected is the function popen/system of the file /cgi-bin/ping.cgi of the component ssi. Executing a manipulation of the argument ipaddr can lead to command injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attack can be launched remotely and requires low privileges. No user interaction is required.
How can I identify systems that may be affected?
Potentially affected systems are TRENDnet TEW-821DAP devices running version 2.2.01b05. The vulnerable functionality is the ssi component's /cgi-bin/ping.cgi endpoint, specifically its ipaddr argument.
What security impact is indicated?
Successful exploitation can lead to command injection through the ipaddr argument. The provided severity data indicates low confidentiality, integrity, and availability impact, with changed scope.