Impact
A stack-based buffer overflow exists in the alphapd component of TRENDnet TV‑IP751WIC firmware version 11.03.03. The flaw is triggered by manipulating input to functions such as SystemNetworkChanged, SystemDDNSChanged, SystemEmailChanged, SystemFTPChanged, websCheckRealm, FUN_00432574 or FUN_0043372C. An attacker can trigger the overflow remotely, potentially leading to arbitrary code execution on the device.
Affected Systems
The vulnerability affects TRENDnet’s TV‑IP751WIC router running firmware 11.03.03. No other firmware versions or related products were confirmed to be impacted by this specific CPE string. The device is exposed to external networks through its web administration, FTP, and email configuration interfaces.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity, and while an EPSS score is not available, the exploit has been publicly released and documented. This means the vulnerability can be actively used by attackers. The device is reachable from outside networks, so remote exploitation is likely. The flaw has no known mitigation from TRENDnet aside from a firmware update, and it is not listed in the CISA KEV catalog, though the public proof‑of‑concept demonstrates feasible exploitation.
OpenCVE Enrichment