Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-75784: TRENDnet TEW-WLC100: Unsecured Server Header Leads to Remote Attack

CVE-2026-75784 · published 16 days ago
Summary

A security flaw in TRENDnet's TEW-WLC100 allows a hacker to remotely attack the device by manipulating a server header. This means a malicious person can access the device from anywhere, potentially causing harm. To protect your device, update to the latest version or consider replacing it with a more secure alternative.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
trendnet tew-wlc100 1v2.07b01
Original advisory text
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipu...
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.
Severity
9.3 Critical
CVSS 2.0: 10.0 (NVD)
CVSS 3.1: 10.0 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS 1%
Type
CWE-119Buffer Overflow
CWE-121Stack-based Buffer Overflow
Timeline
Published18 Aug 2026
Updated30 Aug 2026
First seen18 Aug 2026
Sources
CVE-2026-75784 · MITRE
Monitor software like this
Free during beta