Junglewise Threat Intelligence

CVE-2026-77946: TRENDnet TEW-821DAP stack-based buffer overflow in NTP timezone configuration

CVE-2026-77946 · Severity: critical · CVSS 10 · Published 2026-08-22

Technologies: TRENDnet TEW-821DAP. Vendors: TRENDnet.

Executive brief

TRENDnet TEW-821DAP is a wireless router used to provide internet connectivity and network management. A stack-based buffer overflow vulnerability in the NTP timezone configuration component allows a remote attacker to execute arbitrary code on the device by manipulating specific configuration parameters, potentially leading to complete device compromise or network takeover.

Technical details

A stack-based buffer overflow vulnerability exists in the uci_safe_get function within the /cgi-bin/apply_time.cgi file, which handles NTP timezone configuration. The vulnerability is triggered by manipulating arguments such as system.ntp.server, system.ntp.enable_server, cameo.time.time_zone, or cameo.cameo.syslog_server. The attack is remotely exploitable without requiring authentication. An attacker can leverage this flaw to overflow the stack and achieve arbitrary code execution on the affected device. The vulnerability affects version 2.2.01b05 and earlier versions.

Affected products

  • TRENDnet TEW-821DAP 2.2.01b05 and earlier

Timeline

  • 2026-08-22: disclosed
  • other: Publicly disclosed exploit available

References

Related threats