Executive brief
TRENDnet TEW-821DAP is a wireless router used to provide internet connectivity and network management. A stack-based buffer overflow vulnerability in the NTP timezone configuration component allows a remote attacker to execute arbitrary code on the device by manipulating specific configuration parameters, potentially leading to complete device compromise or network takeover.
Technical details
A stack-based buffer overflow vulnerability exists in the uci_safe_get function within the /cgi-bin/apply_time.cgi file, which handles NTP timezone configuration. The vulnerability is triggered by manipulating arguments such as system.ntp.server, system.ntp.enable_server, cameo.time.time_zone, or cameo.cameo.syslog_server. The attack is remotely exploitable without requiring authentication. An attacker can leverage this flaw to overflow the stack and achieve arbitrary code execution on the affected device. The vulnerability affects version 2.2.01b05 and earlier versions.
Affected products
- TRENDnet TEW-821DAP 2.2.01b05 and earlier
Timeline
- 2026-08-22: disclosed
- other: Publicly disclosed exploit available