Description
A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler. The manipulation leads to stack-based buffer overflow. The attack must be carried out from within the local network. The exploit has been disclosed publicly and may be used.
Published: 2026-08-18
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack-based buffer overflow in the DHCP blobmsg handler within the /sbin/netifd component of TRENDnet TEW‑WLC100P firmware 12.07b01. By sending a specially crafted DHCP request the attacker can overflow a local buffer and may execute arbitrary code with the privileges of the netifd daemon, which could lead to full device compromise.

Affected Systems

The affected product is TRENDnet TEW‑WLC100P with firmware 12.07b01. No other versions are listed; the vulnerability is specific to that firmware build.

Risk and Exploitability

The CVSS score of 9.4 indicates a critical severity. The exploit requires an attacker to be on the same local network, so a compromised client or rogue access point could launch the attack. No EPSS data is available, and the vulnerability is not listed as a known exploited vulnerability in CISA KEV, but the high CVSS suggests it could be prioritized. Local network attackers could use the public proof‑of‑concept found on GitHub to trigger the overflow.

Generated by OpenCVE AI on August 18, 2026 at 14:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a firmware update that addresses the netifd buffer overflow in the DHCP blobmsg handler.
  • Restrict or disable the DHCP blobmsg handler on the device to prevent untrusted payloads.
  • Ensure the device is isolated from untrusted local networks or placed behind a secure gateway that filters DHCP packets.
  • Monitor system logs for abnormal DHCP or netifd activity.

Generated by OpenCVE AI on August 18, 2026 at 14:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Trendnet tew-wlc100p
Vendors & Products Trendnet tew-wlc100p

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler. The manipulation leads to stack-based buffer overflow. The attack must be carried out from within the local network. The exploit has been disclosed publicly and may be used.
Title TRENDnet TEW-WLC100P DHCP blobmsg netifd stack-based overflow
First Time appeared Trendnet
Trendnet tew-wlc100p Firmware
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:o:trendnet:tew-wlc100p_firmware:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-wlc100p Firmware
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:A/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.6, 'vector': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Trendnet Tew-wlc100p Tew-wlc100p Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-18T13:29:24.061Z

Reserved: 2026-08-18T06:49:50.741Z

Link: CVE-2026-75783

cve-icon Vulnrichment

Updated: 2026-08-18T13:29:20.396Z

cve-icon NVD

Status : Received

Published: 2026-08-18T13:17:43.287

Modified: 2026-08-18T14:18:10.200

Link: CVE-2026-75783

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T14:45:03Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow