TRENDnet TEW-821DAP Firmware Update Authentication Bypass Vulnerability Allowing Arbitrary Code Execution

Vulnerability

An authentication vulnerability has been identified in the TRENDnet TEW-821DAP access point, specifically in firmware version 1.12B01. The issue arises in the Firmware Update Handler component, within the functions find_hwid and new_gui_update_firmware. This vulnerability allows for insufficient verification of data authenticity during the firmware update process. The flaw can be exploited remotely, although the complexity of the attack is considered high. The vulnerability stems from hard-coded verification information used for authenticating firmware updates. Attackers could potentially bypass this authentication and upload malicious firmware, leading to arbitrary code execution or a denial-of-service condition by causing the device to become unresponsive.

Impact

Exploitation of this vulnerability could result in unauthorized firmware updates, allowing for arbitrary code execution on the device or causing a denial-of-service by disrupting normal operation.

Added: May 2, 2026, 8:20 AM
Updated: May 2, 2026, 8:20 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
8.7
remediation
0.0
relevance
6.9
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.