CVE-2026-76591: TRENDnet TEW-755AP ssi email.cgi log_email_server command injection
Published Aug 19, 2026
·Updated
A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function logemailserver of the file /cgi-bin/email.cgi of the component ssi. Performing a manipulation results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
1 affected component
Trendnet TEW-755AP<=20260702
Event History
Aug 19, 2026
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is remotely exploitable but requires low privileges. No user interaction is required.
2
Is public exploit information available?
Yes. A public exploit has been released, so affected devices may face an increased likelihood of exploitation.
3
Which component should be prioritized for remediation or exposure review?
Prioritize the ssi component's /cgi-bin/email.cgi endpoint, specifically the log_email_server function. The affected product is reported as TRENDnet TEW-755AP through 20260702.