A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function logemailserver of the file /cgi-bin/email.cgi of the component ssi. Performing a manipulation results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument cameo.wan.wanpppoepassword00 leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.nslookuptarget parameter in the toolsnslookup function.
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the REMOTEUSER parameter in the getaccess (sub45AC2C) function.
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the rejecturl parameter in the reject (sub41BD60) function.
TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the wpsstaenrolleepin parameter in the action setstaenrolleepin5g function.
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reboottype parameter in the wizardipv6 (sub41C380) function.
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wpsstaenrolleepin parameter in the action setstaenrolleepin24g function.
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setbgnum parameter in the icpsetbgimg (sub41DD68) function.
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the loginname parameter in the dographauth (sub4061E0) function.
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstatoption parameter in the toolsnetstat (sub41E730) function.
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the updatefilename parameter in the autoupfw (sub420A04) function.
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstatrsname parameter in the toolsnetstat (sub41E730) function.
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setlogonum parameter in the icpsetlogoimg (sub41DBF4) function.
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the usereditpage parameter in the wificaptiveportal function.
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wpsstaenrolleepin parameter in the dostaenrolleewifi function.
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the delnum parameter in the icpdeleteimg (sub41DEDC) function.
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wpsstaenrolleepin parameter in the setstaenrolleepin5g function.
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%dvap%d.maclist parameter in the kickbanwifimacdeny (sub415D7C) function.
TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the sysservice parameter in the setupwizardmydlink (sub4104B8) function.
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the sysservice parameter in the setupwizardmydlink (sub4104B8) function.
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%dvap%d.maclist parameter in the kickbanwifimacallow (sub415B00) function.
A Format String vulnerablity exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service due to a logic bug at address 0x40dcd0 when calling fprintf with "%s: key len = %d, too long\n" format. The two variables seem to be put in the wrong order. The vulnerability could be triggered by sending the POST request to applycgi with a long and unknown key in the request body.
Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service by sending the POST request to applycgi via the lang action without a language key.
Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03 by sending the POST request to applycgi via a dographauth action without a sessionid key.
Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03 by sending the POST request to applycgi with an unknown action name.
Null Pointer Deference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial os service by sending the POST request to applycgi via action dographauth without loginname key.
Null Pointer Dereference vulnerability in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service by sending a POST request to applycgi via an action pingtest without a pingipaddr key.