CVE-2026-77946: Stack-based Buffer Overflow in TRENDnet TEW-821DAP
CVE-2026-77946 is a critical stack-based buffer overflow vulnerability in TRENDnet TEW-821DAP version 2.2.01b05. The flaw exists in the uci_safe_get function within the /cgi-bin/apply_time.cgi component responsible for NTP Timezone Configuration. Remote attackers can exploit this vulnerability by manipulating specific arguments related to NTP server and timezone settings, potentially leading to a buffer overflow. The exploit has been publicly disclosed but there are no confirmed reports of exploitation in the wild. No official patch or remediation guidance is currently available.
AI Analysis
Technical Summary
This vulnerability affects TRENDnet TEW-821DAP version 2.2.01b05 in the uci_safe_get function of the /cgi-bin/apply_time.cgi script, which handles NTP Timezone Configuration. By remotely manipulating the arguments system.ntp.server, system.ntp.enable_server, cameo.time.time_zone, or cameo.cameo.syslog_server, an attacker can trigger a stack-based buffer overflow. This could allow execution of arbitrary code or cause denial of service. The vulnerability has a CVSS 4.0 base score of 10.0, indicating critical severity with network attack vector, no privileges required, and no user interaction needed. The vulnerability is publicly disclosed but no patch or official fix is documented yet.
Potential Impact
Successful exploitation of this vulnerability can lead to remote code execution or denial of service on the affected device without requiring authentication or user interaction. Given the critical CVSS score and the nature of the buffer overflow, attackers could gain control over the device or disrupt its normal operation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, users should consider limiting network exposure of the affected device and monitor for unusual activity related to NTP configuration requests. No vendor advisory or patch links are currently available.
CVE-2026-77946: Stack-based Buffer Overflow in TRENDnet TEW-821DAP
Description
CVE-2026-77946 is a critical stack-based buffer overflow vulnerability in TRENDnet TEW-821DAP version 2.2.01b05. The flaw exists in the uci_safe_get function within the /cgi-bin/apply_time.cgi component responsible for NTP Timezone Configuration. Remote attackers can exploit this vulnerability by manipulating specific arguments related to NTP server and timezone settings, potentially leading to a buffer overflow. The exploit has been publicly disclosed but there are no confirmed reports of exploitation in the wild. No official patch or remediation guidance is currently available.
CVSS v4.0
Score 10.0critical
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability affects TRENDnet TEW-821DAP version 2.2.01b05 in the uci_safe_get function of the /cgi-bin/apply_time.cgi script, which handles NTP Timezone Configuration. By remotely manipulating the arguments system.ntp.server, system.ntp.enable_server, cameo.time.time_zone, or cameo.cameo.syslog_server, an attacker can trigger a stack-based buffer overflow. This could allow execution of arbitrary code or cause denial of service. The vulnerability has a CVSS 4.0 base score of 10.0, indicating critical severity with network attack vector, no privileges required, and no user interaction needed. The vulnerability is publicly disclosed but no patch or official fix is documented yet.
Potential Impact
Successful exploitation of this vulnerability can lead to remote code execution or denial of service on the affected device without requiring authentication or user interaction. Given the critical CVSS score and the nature of the buffer overflow, attackers could gain control over the device or disrupt its normal operation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, users should consider limiting network exposure of the affected device and monitor for unusual activity related to NTP configuration requests. No vendor advisory or patch links are currently available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-08-21T18:42:40.547Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a8982faacd9273b49ee7313
Added to database: 08/22/2026, 11:07:38 UTC
Last enriched: 08/22/2026, 11:22:04 UTC
Last updated: 08/22/2026, 12:04:27 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.