CVE-2026-4354Disclosure

LOWCVSS 2.0 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in TRENDnet TEW-824DRU 1.010B01/1.04B01. The impacted element is the function sub_420A78 of the file apply_sec.cgi of the component Web Interface. Such manipulation of the argument Language leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-18); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-18: 3Mentions · 2026-03-19: 1Technical Details · 2026-03-18: 203-1803-19
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-183
Disclosure2General1
2026-03-191
General1
Full discourse4 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4354 📊 Severity: 3.5 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4354 #CVE-2026-4354 #CVE #Low  #CyberSecurity #InfoSec https://t.co/FRKt5YbDNV

    Post summary

    The tweet announces a newly disclosed low‑severity CVE with minimal details and no further actionable information.

    0000032
    104 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4354 Cross-Site Scripting in TRENDnet TEW-824DRU Web Interface via Language Parameter https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4354

    Post summary

    A concise CVE entry outlines an XSS flaw in the TRENDnet TEW‑824DRU firmware that exploits the language parameter, with a link to vulmon.com for more details.

    0000029
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4354 A vulnerability was identified in TRENDnet TEW-824DRU 1.010B01/1.04B01. The impacted element is the function sub_420A78 of the file apply_sec.cgi of the component Web I… https://www.cve.org/CVERecord?id=CVE-2026-4354

    Post summary

    A brief disclosure of CVE-2026‑4354 affecting a TRENDnet router’s apply_sec.cgi file, providing only the affected function name without further technical or remediation details.

    00000114
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4354 - TRENDnet TEW-824DRU Web apply_sec.cgi sub_420A78 cross site scripting Intel Report: https://ift.tt/5jnG6wz

    Post summary

    An alert announcing a new cross-site scripting vulnerability (CVE-2026-4354) in TRENDnet TEW-824DRU, with no evidence of exploitation or mitigation yet provided.

    0000036
    335 followersView on X

Explore more