Impact
The flaw is a stack-based buffer overflow triggered by an excessively long Currenttime argument to /cgi-bin/admin/set_time.cgi, allowing a remote attacker to crash the device or potentially execute arbitrary code. The vulnerability provides full control over the device, compromising confidentiality, integrity, and availability, and is exploitable simply by sending a crafted HTTP request. It constitutes a critical remote code execution risk for affected units.
Affected Systems
TRENDnet TV-IP751WIC routers running firmware version 11.03.03 contain the vulnerable /cgi-bin/admin/set_time.cgi component of the alphapd module. The flaw affects the administrative interface exposed by the device.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. While the EPSS score is not available, the exploit is publicly released and can be launched remotely without local privileges. The flaw is not listed in the CISA KEV catalog, yet the public code demonstrates it can be used for attacks against the device from the Internet.
OpenCVE Enrichment