Description
A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function auto_update_firmware of the component Firmware Udpate. The manipulation of the argument str leads to buffer overflow. The attack may be initiated remotely. The vendor explains: "That firmware version will only work on our hardware version v1.xR. We have already EOL that product 8 years ago and are no longer selling". This vulnerability only affects products that are no longer supported by the maintainer.
Problem types
Product status
Timeline
| 2026-05-01: | Advisory disclosed |
| 2026-05-01: | VulDB entry created |
| 2026-05-01: | VulDB entry last update |
Credits
IOT_Res (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/360564 (VDB-360564 | TRENDnet TEW-821DAP Firmware Udpate auto_update_firmware buffer overflow)
vuldb.com/vuln/360564/cti (VDB-360564 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/806214 (Submit #806214 | Trendnet TEW-821DAP v1.12B01 CWE-120 Buffer Copy without Checking Size of Input)
github.com/...are_Update/blob/main/Trendnet/TEW-821DAP_BO.md