← Back to overview

A stack-based buffer overflow vulnerability has been identified in TRENDnet TEW-821DAP version 2.2.01b05. The flaw resides in the uci_safe_get function within the /cgi-bin/apply_time.cgi file, part of the NTP Timezone Configuration Handler component. An attacker can exploit this by manipulating arguments such as system.ntp.server, system.ntp.enable_server, cameo.time.time_zone, and cameo.cameo.syslog_server. The vulnerability can be triggered remotely without physical access to the device. A public exploit has already been disclosed, increasing the risk of active exploitation. The affected device is a wireless access point, making this a concern for network infrastructure security. No patch information is currently noted in the article.

Affected products

  • TRENDnet TEW-821DAP 2.2.01b05

Related CVE's

  • CVE-2026-77946

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities