{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/tv-ip751wic/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TV-IP751WIC"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["TRENDnet"],"content_html":"\u003cp\u003eA critical stack-based buffer overflow vulnerability has been identified in the TRENDnet TV-IP751WIC network camera, specifically within the 'alphapd' web server component. The vulnerability, tracked as CVE-2026-75877, affects firmware version 11.03.03. The issue stems from improper boundary management within several administrative and configuration functions, including SystemNetworkChanged, SystemDDNSChanged, SystemEmailChanged, SystemFTPChanged, and websCheckRealm.\u003c/p\u003e\n\u003cp\u003eAn attacker can trigger this overflow remotely by sending a specifically crafted request to these functions, leading to memory corruption. Because the 'alphapd' component runs as a core service, successful exploitation may allow for unauthenticated or low-privileged remote code execution. Proof-of-concept exploit code has been publicly released, increasing the risk of immediate exploitation. This vulnerability is particularly severe due to the remote, unauthenticated nature of the potential exploit chain and the administrative reach of the affected component.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify internet-facing TRENDnet TV-IP751WIC devices.\u003c/li\u003e\n\u003cli\u003eAttacker probes the device to confirm the target firmware version (11.03.03).\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP request targeting one of the identified vulnerable functions (e.g., SystemNetworkChanged).\u003c/li\u003e\n\u003cli\u003eAttacker includes an overly large payload within the request parameters to initiate a stack-based buffer overflow in the alphapd binary.\u003c/li\u003e\n\u003cli\u003eThe alphapd service fails to validate input length, resulting in the overwrite of the return address on the stack.\u003c/li\u003e\n\u003cli\u003eThe process redirects execution flow to the attacker-supplied shellcode embedded in the payload.\u003c/li\u003e\n\u003cli\u003eAttacker gains arbitrary code execution with the privileges of the alphapd process.\u003c/li\u003e\n\u003cli\u003eAttacker establishes persistence or pivots into the internal network from the compromised camera.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS 3.1 base score of 9.9, representing a critical risk. Successful exploitation allows for complete compromise of the affected camera, leading to loss of confidentiality, integrity, and availability. Potential impacts include unauthorized access to video feeds, lateral movement into internal enterprise networks from the IoT device, and potential device bricking.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately isolate all TRENDnet TV-IP751WIC devices from the public internet using firewalls or VPN requirements.\u003c/li\u003e\n\u003cli\u003eMonitor internal network traffic originating from IoT segments for anomalous connections to or from these devices.\u003c/li\u003e\n\u003cli\u003ePatch the affected devices if a firmware update is released by the vendor; prioritize decommissioning devices if no patch is available for the 11.03.03 version.\u003c/li\u003e\n\u003cli\u003eRestrict administrative access to the web interface to trusted management VLANs only.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-18T21:00:12Z","date_published":"2026-08-18T21:00:12Z","id":"https://feed.craftedsignal.io/briefs/2026-08-trendnet-overflow/","summary":"A critical stack-based buffer overflow vulnerability (CVE-2026-75877) in the TRENDnet TV-IP751WIC alphapd component allows remote attackers to execute arbitrary code via multiple affected functions.","title":"Remote Stack-based Buffer Overflow in TRENDnet TV-IP751WIC","url":"https://feed.craftedsignal.io/briefs/2026-08-trendnet-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - TV-IP751WIC","version":"https://jsonfeed.org/version/1.1"}