CVE-2026-75976: TRENDnet TEW-823DRU NVRAM wan.cgi strcpy stack-based overflow
Published Aug 18, 2026
·Updated
A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM. This manipulation of the argument wanl2tppassword causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
1 affected component
Trendnet TEW-823DRU=1.1.02b01
Event History
Aug 18, 2026
CVE Published
via MITRE·11:30 PM
Data Sourced
via MITRE·11:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
TRENDnet TEW-823DRU devices running version 1.1.02b01 are identified as affected. The vulnerable code is in the NVRAM component's /cgi-bin/wan.cgi endpoint.
2
What access does an attacker need to exploit it?
The attack can be initiated remotely, but the severity vector indicates low privileges are required. No user interaction is required.
3
Is public exploit code available?
Yes. The exploit has been made public and could be used in attacks.