CVE-2026-76584: TRENDnet TV-IP751WIC alphapd set_time.cgi stack-based overflow
A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin/settime.cgi of the component alphapd. The manipulation of the argument Currenttime results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require authentication or user interaction?
An attacker needs low-level privileges to exploit the issue, but no user interaction is required. The attack can be launched remotely over the network.
What could a successful exploit allow an attacker to do?
The assigned vector indicates high impacts to confidentiality, integrity, and availability, with a scope change. This means successful exploitation could affect the device and potentially resources beyond the initially compromised security authority.
How likely is active exploitation?
Public exploit code has been released and may be used in attacks. Systems running the affected version should be treated as exposed if a low-privileged attacker can reach the device remotely.