Data Authenticity Vulnerability in TRENDnet TEW-821DAP Firmware Update Handler
CVE-2026-7611

6.3MEDIUM

Key Information:

Vendor

Trendnet

Vendor
CVE Published:
2 May 2026

What is CVE-2026-7611?

A vulnerability exists in the TRENDnet TEW-821DAP firmware update handler, specifically within the 'platform_do_upgrade_cameo_dev' function located in the 'cameo_dev.sh' script. This flaw allows for insufficient verification of data authenticity, which may enable attackers to conduct remote manipulations. Notably, this issue is present in firmware versions up to 1.12B01 and affects hardware version v1.xR, which has been out of support for the last eight years. Given the complexity of the attack, the potential exploitation remains challenging, particularly because the affected product is no longer sold or maintained by TRENDnet.

Affected Version(s)

TEW-821DAP 1.12B01

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

IOT_Res (VulDB User)
VulDB CNA Team
.