Description
A vulnerability was identified in TRENDnet TV-IP751WIC 11.03.03. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The manipulation leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
Published: 2026-08-19
Score: 5.3 Medium
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A command injection flaw exists in the /cgi-bin/admin/set_time.cgi component of TRENDnet TV-IP751WIC. The flaw allows an attacker to inject arbitrary shell commands, which are executed with the privileges of the web service running on the device. This can lead to full compromise of the device, including unauthorized configuration changes, data exfiltration, or usage as a pivot point for further network attacks. The vulnerability results from unsanitized input is classified under CWE‑74 and CWE‑77.

Affected Systems

The affected product is TRENDnet TV-IP751WIC, specifically firmware version 11.03.03. No other versions are documented as impacted. The device exposes the vulnerable CGI script over HTTP, making it reachable from any network that can reach the device's management interface.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the exploit is publicly available. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote over the network, as the CGI script can be accessed from any host with network connectivity to the device. An attacker can exploit this by sending a crafted HTTP request containing malicious commands, leading to remote code execution on the device.

Generated by OpenCVE AI on August 20, 2026 at 08:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from TRENDnet that addresses the command injection flaw
  • If a patch is not immediately available, block or restrict external access to /cgi-bin/admin/set_time.cgi or enforce IP‑based access controls on the device
  • Continuously monitor device logs for suspicious HTTP requests containing injected commands

Generated by OpenCVE AI on August 20, 2026 at 08:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in TRENDnet TV-IP751WIC 11.03.03. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The manipulation leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
Title TRENDnet TV-IP751WIC alphapd set_time.cgi command injection
First Time appeared Trendnet
Trendnet tv-ip751wic
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:trendnet:tv-ip751wic:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tv-ip751wic
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


Subscriptions

Trendnet Tv-ip751wic
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-20T18:21:38.293Z

Reserved: 2026-08-19T14:08:11.181Z

Link: CVE-2026-76583

cve-icon Vulnrichment

Updated: 2026-08-20T18:21:33.247Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T21:17:38.643

Modified: 2026-08-20T19:17:04.297

Link: CVE-2026-76583

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T08:15:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')