Sceawere
Vulnerability Detail
CVE-2026-76590UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
TRENDnet TEW-755AP Buffer Overflow
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 19h ago
- Vendor
- TRENDnet
- Product
- TEW-755AP
- Attack Type
- Stack-based Buffer Overflow
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument cameo.wan.wan_pppoe_password_00 leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-08-19T22:17:27.613Z",
"pubdate": "2026-08-19T22:17:27.613Z",
"executiveSummary": "A stack-based buffer overflow vulnerability has been identified in TRENDnet TEW-755AP devices up to version 20260702.\nThe vulnerability resides within the ssi component, specifically inside the /cgi-bin/wan.cgi binary via the manipulation of the cameo.wan.wan_pppoe_password_00 argument.\nSuccessful exploitation of this flaw allows remote attackers to execute arbitrary code or cause a denial of service by sending a crafted HTTP request.\nThe vulnerability poses a severe risk to network integrity and confidentiality as it can be triggered remotely without complex authentication preconditions.\nAn exploit is publicly available, significantly increasing the likelihood of active exploitation in the wild.\nAffected systems require immediate security patching or network segmentation to mitigate unauthorized remote access risks.",
"technicalDetails": "The vulnerability is a classic stack-based buffer overflow stemming from unsafe handling of user-supplied input within the ssi component of TRENDnet TEW-755AP up to version 20260702.\nSpecifically, the flaw manifests when processing HTTP requests directed at the /cgi-bin/wan.cgi script.\nThe vulnerable parameter identified during analysis is cameo.wan.wan_pppoe_password_00, which fails to implement adequate boundary checks or input length validation before copying the supplied string into a fixed-size stack buffer.\nWhen a remote attacker supplies an excessively long payload within the cameo.wan.wan_pppoe_password_00 argument, the input exceeds the memory allocation boundaries of the destination buffer.\nThis overflow overwrites adjacent stack memory, including saved frame pointers and return addresses.\nUpon function return, the instruction pointer is redirected to attacker-controlled memory locations if a carefully crafted payload containing shellcode and return-oriented programming (ROP) chains is utilized.\nThe attack flow requires network connectivity to the targeted device's web administration interface, exposing the attack vector remotely.\nDepending on the privilege context of the running httpd or ssi binary, successful code execution typically grants the attacker administrative or root-level control over the embedded Linux operating system running on the TRENDnet TEW-755AP.\nPost-exploitation impact includes complete device compromise, interception of network traffic, persistence via firmware modification, and pivoting into the internal local area network."
}