Description
A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument cameo.wan.wan_pppoe_password_00 leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
Published: 2026-08-19
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack-based buffer overflow exists in the /cgi-bin/wan.cgi component of TRENDnet TEW‑755AP. By manipulating the cameo.wan.wan_pppoe_password_00 argument, an attacker can overflow a stack buffer, potentially gaining complete control of the device. This flaw allows remote attackers to execute arbitrary code, leading to full system compromise.

Affected Systems

TRENDnet TEW‑755AP routers with firmware versions up to 20260702 are affected. The vulnerability is present in the ssi component of the wan.cgi CGI script of these devices.

Risk and Exploitability

The vulnerability is rated CVSS 9.4, indicating critical severity. The EPSS score is not available, but exploitation is publicly possible as documented online. Although the flaw is not listed in the CISA KEV catalog, its public exploitability and remote nature make it a high‑risk condition for exposed devices.

Generated by OpenCVE AI on August 20, 2026 at 08:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a vendor firmware update newer than 20260702 that resolves the buffer overflow in wan.cgi.
  • If a timely update is unavailable, block or disable the /cgi-bin/wan.cgi endpoint via the device’s firewall or by editing the web server configuration to restrict access to trusted IP ranges.
  • Configure network segmentation or a perimeter firewall so that the router’s web interface is not reachable from untrusted networks.
  • Monitor router logs for abnormal POST requests to wan.cgi and investigate any suspicious activity promptly.

Generated by OpenCVE AI on August 20, 2026 at 08:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Trendnet tew-755ap
Vendors & Products Trendnet tew-755ap

Wed, 19 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument cameo.wan.wan_pppoe_password_00 leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
Title TRENDnet TEW-755AP ssi wan.cgi stack-based overflow
First Time appeared Trendnet
Trendnet tew-755ap Firmware
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:o:trendnet:tew-755ap_firmware:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-755ap Firmware
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Trendnet Tew-755ap Tew-755ap Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-21T16:47:12.380Z

Reserved: 2026-08-19T14:38:01.742Z

Link: CVE-2026-76590

cve-icon Vulnrichment

Updated: 2026-08-21T16:47:07.219Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T22:17:27.613

Modified: 2026-08-21T17:16:46.000

Link: CVE-2026-76590

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T08:30:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow