Impact
A stack-based buffer overflow exists in the /cgi-bin/wan.cgi component of TRENDnet TEW‑755AP. By manipulating the cameo.wan.wan_pppoe_password_00 argument, an attacker can overflow a stack buffer, potentially gaining complete control of the device. This flaw allows remote attackers to execute arbitrary code, leading to full system compromise.
Affected Systems
TRENDnet TEW‑755AP routers with firmware versions up to 20260702 are affected. The vulnerability is present in the ssi component of the wan.cgi CGI script of these devices.
Risk and Exploitability
The vulnerability is rated CVSS 9.4, indicating critical severity. The EPSS score is not available, but exploitation is publicly possible as documented online. Although the flaw is not listed in the CISA KEV catalog, its public exploitability and remote nature make it a high‑risk condition for exposed devices.
OpenCVE Enrichment