CVE-2026-75784RCE por desbordamiento de búfer en TRENDnet TEW-WLC100
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.
Ver en NVDAnálisis
Esta vulnerabilidad en el controlador TRENDnet TEW-WLC100 permite la ejecución remota de código mediante un desbordamiento de búfer en el procesamiento de cabeceras HTTP de su servicio nginx. Debido a que existe un exploit público, cualquier atacante puede comprometer la infraestructura de red que utilice este dispositivo. Es fundamental actualizar el firmware para evitar el control total del equipo por parte de terceros.
Roles relevantes
Severidad
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCWE-119CWE-121EPSS
Sin puntaje EPSS aún (CVE muy reciente).
Descripción técnica
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.
Referencias
- https://github.com/meishigana/CVE/blob/main/team15_20260702/02_wlc100-nginx/poc/poc-nginx-overflow.py
- https://github.com/meishigana/CVE/tree/main/team15_20260702/02_wlc100-nginx
- https://vuldb.com/cve/CVE-2026-75784
- https://vuldb.com/submit/877773
- https://vuldb.com/vuln/391525
- https://vuldb.com/vuln/391525/cti