What is CVE-2026-75984?
A command injection vulnerability has been found in TRENDnet TEW-823DRU version 1.1.02b01, affecting an unknown function in `/cgi-bin/admin.cgi` via the Hostname argument. This flaw allows remote code execution and the exploit is publicly available. It is recommended to update the firmware or isolate the management interface from the network until a patch is provided.
Azərbaycanca: TRENDnet TEW-823DRU 1.1.02b01 modelində, `/cgi-bin/admin.cgi` faylındakı Hostname arqumentində command injection zəifliyi aşkar edilib. Bu zəiflik uzaqdan kod icrasına imkan verir və istismar kodu ictimaiyyətə açıqdır. Cihazın firmware-ini yeniləmək və ya istehsalçıdan yamaq təmin olunana qədər idarəetmə interfeysini şəbəkədən təcrid etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: TRENDnet
FAQ2
How does CVE-2026-75984 affect the TRENDnet TEW-823DRU device?
This vulnerability allows command injection via the Hostname argument in the `/cgi-bin/admin.cgi` file, which can lead to remote code execution. The exploit code is already publicly available.
What temporary mitigation is recommended for CVE-2026-75984?
If a firmware update is not available, it is recommended to isolate the management interface from the network until a patch is provided by the manufacturer.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.