Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-75784RCE por desbordamiento de búfer en TRENDnet TEW-WLC100

A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.

Ver en NVD

Análisis

Esta vulnerabilidad en el controlador TRENDnet TEW-WLC100 permite la ejecución remota de código mediante un desbordamiento de búfer en el procesamiento de cabeceras HTTP de su servicio nginx. Debido a que existe un exploit público, cualquier atacante puede comprometer la infraestructura de red que utilice este dispositivo. Es fundamental actualizar el firmware para evitar el control total del equipo por parte de terceros.

Roles relevantes

HardwareCyberSecurityBackendLinuxC

Severidad

Puntaje: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-119CWE-121

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.

Publicada: 18/8/2026, 15:17:13
Última modificación: 18/8/2026, 15:17:13

Referencias

InicioEventosBlogRecursosCursosEquipo