CVE-2026-75784Stack-based Buffer Overflow RCE in TRENDnet TEW-WLC100
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.
View on NVDAnalysis
Esta vulnerabilidad en el controlador TRENDnet TEW-WLC100 permite la ejecución remota de código mediante un desbordamiento de búfer en el procesamiento de cabeceras HTTP de su servicio nginx. Debido a que existe un exploit público, cualquier atacante puede comprometer la infraestructura de red que utilice este dispositivo. Es fundamental actualizar el firmware para evitar el control total del equipo por parte de terceros.
Relevant roles
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCWE-119CWE-121EPSS
No EPSS score yet (CVE may be too fresh).
Technical description
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.
References
- https://github.com/meishigana/CVE/blob/main/team15_20260702/02_wlc100-nginx/poc/poc-nginx-overflow.py
- https://github.com/meishigana/CVE/tree/main/team15_20260702/02_wlc100-nginx
- https://vuldb.com/cve/CVE-2026-75784
- https://vuldb.com/submit/877773
- https://vuldb.com/vuln/391525
- https://vuldb.com/vuln/391525/cti