CVE-2026-76582
published 2026-08-19CVE-2026-76582: A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected is the function popen/system of the file /cgi-bin/ping.cgi of the component ssi…
PriorityP356high7.4CVSS 3.1
AVNACLPRLUINSCCLILAL
EPSS
1.28%
68.8th percentile
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected is the function popen/system of the file /cgi-bin/ping.cgi of the component ssi. Executing a manipulation of the argument ipaddr can lead to command injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| trendnet | tew-821dap | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
TRENDnet TEW-821DAP 2.2.01b05 ssi /cgi-bin/ping.cgi popen/system ipaddr command injection
vuldb·2026-08-23·CVSS 7.4
CVE-2026-76582 [HIGH] TRENDnet TEW-821DAP 2.2.01b05 ssi /cgi-bin/ping.cgi popen/system ipaddr command injection
A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05 and classified as critical. Affected is the function popen/system of the file /cgi-bin/ping.cgi of the component ssi. Executing a manipulation of the argument ipaddr can lead to command injection.
This vulnerability is registered as CVE-2026-76582. It is possible to launch the attack remotely. Furthermore, an exploit is available.
GHSA
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05.
ghsa_unreviewed·2026-08-19
CVE-2026-76582 [LOW] CWE-74 A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05.
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected is the function popen/system of the file /cgi-bin/ping.cgi of the component ssi. Executing a manipulation of the argument ipaddr can lead to command injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-19
Published