Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-77946Desbordamiento de búfer en TRENDnet TEW-821DAP

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation of the argument system.ntp.server/system.ntp.enable_server/cameo.time.time_zone/cameo.cameo.syslog_server can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

Ver en NVD

Análisis

Esta vulnerabilidad crítica en puntos de acceso TRENDnet TEW-821DAP permite la ejecución remota de código mediante un desbordamiento de búfer en la configuración de NTP. Al existir un exploit público disponible, los atacantes pueden comprometer el dispositivo de forma remota sin autenticación previa.

Roles relevantes

HardwareciberseguridadCLinux

Severidad

Puntaje: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-119CWE-121

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation of the argument system.ntp.server/system.ntp.enable_server/cameo.time.time_zone/cameo.cameo.syslog_server can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

Publicada: 22/8/2026, 11:16:54
Última modificación: 22/8/2026, 11:16:54

Referencias

InicioEventosBlogRecursosCursosEquipo