Impact
The defect lies in the FUN_401000 routine of the /sbin/mycli binary, where the ssid argument is processed without proper bounds checking. A malicious actor can supply a crafted SSID value that overflows the local stack buffer, corrupting control data and allowing execution of arbitrary code. The CVE report states the exploit can be launched remotely, meaning any entity able to contact the device over its management interface may trigger the overflow.
Affected Systems
TRENDnet TEW‑755AP wireless routers running firmware versions up to and including 20260702 are vulnerable. Firmware releases later than 20260702 contain a fix that removes the vulnerability. No other product variants or versions are listed as affected.
Risk and Exploitability
The calculated CVSS score of 9.4 classifies this issue as critical, and although EPSS data is unavailable, the public proof‑of‑concept script and the fact that the flaw can be triggered from outside the local network elevate the likelihood of exploitation. The vulnerability is not yet catalogued in CISA KEV, but the remote nature of the attack combined with the severity score suggests that attackers would target these devices opportunistically. The attack vector is remote and requires only domain knowledge of the device’s management protocol and the ability to send a specially crafted SSID string.
OpenCVE Enrichment