CVE-2026-7608Disclosure(trendnet / tew-821dap)

LOWCVSS 8.0 · HIGH

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for trendnet tew-821dap systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was detected in TRENDnet TEW-821DAP up to 1.12B01. The affected element is the function tools_diagnostic. The manipulation results in os command injection. The exploit is now public and may be used. The vendor explains: "That firmware version will only work on our hardware version v1.xR. We have already EOL that product 8 years ago and are no longer selling". This vulnerability only affects products that are no longer supported by the maintainer.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tew-821dap
  • tew-821dap_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
tew-821daptew-821dap_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-02: 3Active Exploitation · 2026-05-02: 1Technical Details · 2026-05-02: 305-02
Signal classification2 categories
Disclosure
266.7%
Exploit
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7608 A vulnerability was detected in TRENDnet TEW-821DAP up to 1.12B01. The affected element is the function tools_diagnostic. The manipulation results in os command injecti… https://www.cve.org/CVERecord?id=CVE-2026-7608

    Post summary

    The post announces an OS command injection vulnerability (CVE‑2026‑7608) in the tools_diagnostic function of TRENDnet TEW‑821DAP firmware versions up to 1.12B01.

    00010362
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Exploit

    CVE-2026-7608 OS Command Injection in TRENDnet TEW-821DAP Up to 1.12B01 (Exploitation Public) https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7608

    Post summary

    The post identifies CVE-2026-7608 as an OS command injection vulnerability in TRENDnet routers, noting that exploitation is public but does not provide PoC code, a patch, or evidence of real‑world attacks.

    0000059
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7608 A vulnerability was detected in TRENDnet TEW-821DAP up to 1.12B01. The affected element is the function tools_diagnostic. The manipulation results in os command injecti… https://www.cve.org/CVERecord?id=CVE-2026-7608 ----- Traducción: CVE-2026-7608 Se … http://infoflow.cloud`

    Post summary

    The post reports that CVE‑2026‑7608 was detected in TRENDnet TEW‑821DAP routers, describing an OS command injection via the tools_diagnostic function, but does not mention a PoC, exploit code, patch, or active exploitation.

    0000029
    75 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtrendnettew-821dap1.0r--
OStrendnettew-821dap_firmware1.12b01--

Explore more