CVE-2026-7610 Details
Description
A vulnerability has been found in TRENDnet TEW-821DAP 1.12B01. This affects an unknown function of the file /www/cgi/ssi of the component Firmware Update. Such manipulation leads to cleartext transmission of sensitive information. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is reported as difficult. The exploit has been disclosed to the public and may be used. The vendor explains: "That firmware version will only work on our hardware version v1.xR. We have already EOL that product 8 years ago and are no longer selling". This vulnerability only affects products that are no longer supported by the maintainer.
A vulnerability exists in the TRENDnet TEW-821DAP access point, specifically in firmware version 1.12B01. The issue arises in the firmware update process, where the device uses a hard-coded URL for downloading firmware via HTTP, rather than a secure HTTPS connection. This flaw exposes the download to potential man-in-the-middle attacks, allowing attackers to intercept the firmware URL and possibly redirect it to a malicious site or modify the firmware before it is installed. The vulnerability enables remote exploitation, but is considered to have high complexity and difficult exploitability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Trendnet/TEW-821DAP_Down.md | [email protected] | ExploitThird Party Advisory |
| https://vuldb.com/submit/806217 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/vuln/360567 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/vuln/360567/cti | [email protected] | Permissions RequiredVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-310 | Cryptographic Issues | [email protected] |
| CWE-319 | Cleartext Transmission of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| trendnet tew-821dap firmware | 1.12b01 |
CPE
Remediation
| |
| trendnet tew-821dap | 1.0r |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 6, 2026 | Initial Analysis | [email protected] |
| May 2, 2026 | New CVE Received | [email protected] |