Skip to content
Threat Feed

Vendor

Trendnet

11 briefs RSS
high advisory

Remote Command Injection in TRENDnet TEW-821DAP

TRENDnet TEW-821DAP firmware version 2.2.01b05 is vulnerable to remote command injection via the /cgi-bin/ping.cgi endpoint, allowing authenticated attackers to execute arbitrary system commands.

TEW-821DAP command-injection network-device vulnerability
1r 1t 1c
critical threat

Stack-based Buffer Overflow in TRENDnet TEW-755AP Access Points

A critical stack-based buffer overflow vulnerability in the /sbin/mycli binary of TRENDnet TEW-755AP access points allows remote unauthenticated attackers to execute arbitrary code via the 'ssid' argument.

exploited TEW-755AP remote-code-execution buffer-overflow iot networking vulnerability network-security cve-2026-76590 cve-2026-76591 +2
2r 3t 1c
high advisory

Command Injection in TRENDnet Router via /cgi-bin/ping.cgi

A command injection vulnerability in TRENDnet Router 1.1.02b01 allows remote, authenticated attackers to execute arbitrary commands by manipulating the wan_type parameter.

Router cve-2026-75985 command-injection network-security
1r 1t 1c
critical advisory

Remote Stack-based Buffer Overflow in TRENDnet TV-IP751WIC

A critical stack-based buffer overflow vulnerability (CVE-2026-75877) in the TRENDnet TV-IP751WIC alphapd component allows remote attackers to execute arbitrary code via multiple affected functions.

TV-IP751WIC vulnerability cve iot rce
2r 3t updated
critical advisory

Critical Stack-Based Buffer Overflow in TRENDnet TEW-WLC100

A critical stack-based buffer overflow in the TRENDnet TEW-WLC100 HTTP Header Handler allows remote attackers to achieve arbitrary code execution via a malformed 'Server' header.

TEW-WLC100 cve-2026-75784 buffer-overflow remote-code-execution network-security
1r 1t 1c
high advisory

Remote Buffer Overflow Vulnerability in TRENDnet TEW-821DAP Access Point

A critical buffer overflow vulnerability (CVE-2026-15484) exists in the `sub_41EC14` function within the `/goform/tools_nslookup` component of the TRENDnet TEW-821DAP 1.12B01 wireless access point, which can be exploited remotely due to improper handling of the ssi element, potentially leading to arbitrary code execution on an End-of-Life device.

TEW-821DAP buffer-overflow vulnerability network-device remote-code-execution
1c
high advisory

Remote Command Injection in Trendnet TEW-635BRM Routers (CVE-2026-15481)

A critical remote command injection vulnerability (CVE-2026-15481) has been discovered in Trendnet TEW-635BRM routers up to version 1.00.03, allowing attackers to execute arbitrary commands by manipulating the 'ipoa_ipaddr' argument in the 'ipoa_test' function, with public exploits available for this End-of-Life product.

TEW-635BRM command-injection remote-code-execution network-device EOL-product
1t 1c
high advisory

Trendnet TEW-635BRM Web Service Stack-based Buffer Overflow Vulnerability

CVE-2026-15480 describes a stack-based buffer overflow vulnerability in the Trendnet TEW-635BRM router firmware, specifically in the start_httpd function within the /sbin/rc component's Web Service, which can be exploited remotely by manipulating the 'device_name' argument, potentially leading to arbitrary code execution; an exploit is publicly available, but the product is End-of-Life (EOL) since 2011, and the vendor advises users to switch devices.

TEW-635BRM network vulnerability router buffer-overflow rce eol
2t 1c
high advisory

TRENDnet TEW-432BRP Stack-Based Buffer Overflow Vulnerability (CVE-2026-10123)

A stack-based buffer overflow vulnerability (CVE-2026-10123) exists in TRENDnet TEW-432BRP version 3.10B20 within the formSetDomainFilter function, allowing a remote attacker to execute arbitrary code by manipulating specific arguments in a request to /goform/formSetDomainFilter.

TEW-432BRP 3.10B20 cve buffer overflow remote code execution network device
2r 1t 1c
high advisory

TRENDnet TEW-432BRP Stack-Based Buffer Overflow Vulnerability (CVE-2026-10062)

TRENDnet TEW-432BRP version 3.10B20 is vulnerable to a stack-based buffer overflow via manipulation of the ip/mask/gateway arguments in the formSetRoute function of the /goform/formSetRoute file, enabling remote attackers to potentially execute arbitrary code.

TEW-432BRP 3.10B20 cve buffer-overflow router
2r 1c
medium advisory

TRENDnet TEW-821DAP Firmware Update Buffer Overflow Vulnerability

A buffer overflow vulnerability exists in TRENDnet TEW-821DAP version 1.12B01, allowing a remote attacker to execute arbitrary code by manipulating the 'str' argument in the auto_update_firmware function of the Firmware Update component.

TEW-821DAP buffer-overflow firmware-update network-device
2r 1t 1c