CVE-2026-77945: Command Injection in TRENDnet TEW-821DAP
Description
CVE-2026-77945 is a command injection vulnerability in the TRENDnet TEW-821DAP router version 2.2.01b05. It occurs in the /cgi-bin/upload.cgi file within the ssi component, where manipulation of the filename argument can lead to remote command execution. The vulnerability has a medium severity score of 5.3 and an exploit has been publicly disclosed, though no known active exploitation in the wild is reported.
CVSS v4.0
Score 5.3medium
Affected software
TRENDnet
TEW-821DAP
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability affects TRENDnet TEW-821DAP version 2.2.01b05. The issue is a command injection flaw in an unspecified function of /cgi-bin/upload.cgi in the ssi component. An attacker can remotely manipulate the filename argument to execute arbitrary commands on the device. The CVSS 4.0 base score is 5.3, indicating medium severity. The vulnerability is publicly known and exploit code is available, but no confirmed in-the-wild exploitation has been observed.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary commands on the affected device, potentially compromising the router's integrity and confidentiality. This could lead to unauthorized control or disruption of network traffic managed by the device.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict remote access to the device's management interface and monitor for suspicious activity related to the upload.cgi endpoint.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-08-21T18:41:56.089Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8982faacd9273b49ee7315
Added to database: 08/22/2026, 11:07:38 UTC
Last enriched: 09/11/2026, 02:03:58 UTC
Last updated: 10/06/2026, 18:48:25 UTC
Views: 64
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.