SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-75976

CRITICAL · CVSS 9.9 EPSS 0.63% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A critical vulnerability exists in the TRENDnet TEW-823DRU router, specifically within the strcpy function in the /cgi-bin/wan.cgi file, which is susceptible to a stack-based buffer overflow due to improper handling of the wan_l2tp_password argument. This flaw allows remote attackers to exploit the vulnerability, potentially leading to unauthorized access or control over the device. Organizations using this router model should prioritize immediate patching or mitigation strategies to safeguard their networks against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75976
Severity
CRITICAL
CVSS
9.9
EPSS
0.63%

Original NVD Description

A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM. This manipulation of the argument wan_l2tp_password causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.