CVE-2026-76590: TRENDnet TEW-755AP ssi wan.cgi stack-based overflow
A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument cameo.wan.wanpppoepassword00 leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack is remotely executable and requires low privileges (PR:L). No user interaction is required.
How serious is successful exploitation?
The provided vector indicates high impacts to confidentiality, integrity, and availability, with scope changed. A public exploit is available and may be used.
Which systems are reported as affected?
The issue is reported in TRENDnet TEW-755AP devices up to 20260702. The affected input is the cameo.wan.wan_pppoe_password_00 argument handled by /cgi-bin/wan.cgi.