---
id: CVE-2026-77988
title: A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01
summary: >-
  A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. This
  vulnerability affects the function nvram_get of the component CLI
  Configuration Tool. This manipulation causes command injection. The attack is
  possible to be carried …
severity: medium
cvss: 6.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-77
published: '2026-08-22'
updated: '2026-08-22'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77988'
references:
  - url: >-
      https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/TEW-823DRU_bin_cli_NVRAM_Command_Injection.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-77988'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/881256'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/394178'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/394178/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-08-23T04:42:14.018Z'
epss: 0.02399
epssPercentile: 0.83297
---

## Overview

A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. This vulnerability affects the function nvram_get of the component CLI Configuration Tool. This manipulation causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
