Description
A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/SystemDDNSChanged/SystemEmailChanged/SystemFTPChanged/websCheckRealm/FUN_00432574/FUN_0043372C of the component alphapd. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
Published: 2026-08-18
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack-based buffer overflow exists in the alphapd component of TRENDnet TV‑IP751WIC firmware version 11.03.03. The flaw is triggered by manipulating input to functions such as SystemNetworkChanged, SystemDDNSChanged, SystemEmailChanged, SystemFTPChanged, websCheckRealm, FUN_00432574 or FUN_0043372C. An attacker can trigger the overflow remotely, potentially leading to arbitrary code execution on the device.

Affected Systems

The vulnerability affects TRENDnet’s TV‑IP751WIC router running firmware 11.03.03. No other firmware versions or related products were confirmed to be impacted by this specific CPE string. The device is exposed to external networks through its web administration, FTP, and email configuration interfaces.

Risk and Exploitability

The CVSS score of 9.4 indicates critical severity, and while an EPSS score is not available, the exploit has been publicly released and documented. This means the vulnerability can be actively used by attackers. The device is reachable from outside networks, so remote exploitation is likely. The flaw has no known mitigation from TRENDnet aside from a firmware update, and it is not listed in the CISA KEV catalog, though the public proof‑of‑concept demonstrates feasible exploitation.

Generated by OpenCVE AI on August 18, 2026 at 21:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the TV‑IP751WIC firmware to the latest version that contains a patch for this vulnerability, as provided by TRENDnet.
  • If a patch is not available, place the device behind a firewall or in an isolated VLAN and disable remote management services such as web administration, FTP, and email configuration to limit exposure.
  • Monitor device logs for abnormal activity and use network segmentation monitoring to detect attempts to trigger the overflow.

Generated by OpenCVE AI on August 18, 2026 at 21:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Description A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/SystemDDNSChanged/SystemEmailChanged/SystemFTPChanged/websCheckRealm/FUN_00432574/FUN_0043372C of the component alphapd. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
Title TRENDnet TV-IP751WIC alphapd FUN_0043372C stack-based overflow
First Time appeared Trendnet
Trendnet tv-ip751wic
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:a:trendnet:tv-ip751wic:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tv-ip751wic
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Trendnet Tv-ip751wic
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-19T13:10:11.358Z

Reserved: 2026-08-18T12:35:11.727Z

Link: CVE-2026-75877

cve-icon Vulnrichment

Updated: 2026-08-19T13:10:03.530Z

cve-icon NVD

Status : Received

Published: 2026-08-18T20:17:33.340

Modified: 2026-08-19T13:18:11.260

Link: CVE-2026-75877

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T22:00:14Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow