A critical vulnerability (CVE-2026-75784) has been identified in TRENDnet TEW-WLC100 firmware version 1v2.07b01. The flaw exists in the HTTP Header Handler component of the embedded nginx web server (file /usr/nginx/sbin/nginx), specifically within function FUN_0040da4c. A stack-based buffer overflow is triggered by manipulating the 'Server' argument in HTTP headers, enabling remote attackers to execute arbitrary code. The vulnerability affects the TRENDnet TEW-WLC100 appliance and its bundled nginx implementation. With a CVSS score of 10.0, this issue represents a severe risk due to remote exploitability and the availability of public proof-of-concept code. Immediate mitigation requires applying firmware updates from the vendor. Network administrators are advised to block unnecessary HTTP header modifications at perimeter firewalls until patches are deployed.
CRITICAL
CVSS 10.0
CVE-2026-75784
2026-08-19
Critical Stack-Based Buffer Overflow in TRENDnet TEW-WLC100 (CVE-2026-75784)
A critical stack-based buffer overflow vulnerability in TRENDnet TEW-WLC100 1v2.07b01 allows remote code execution via manipulated HTTP headers. Public exploits are available.