CVE-2026-77946: TRENDnet Tew-821dap

Critical severity, CVSS 10.0. EPSS: 1% chance of exploitation in the next 30 days.

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation of the argument system.ntp.server/system.ntp.enable_server/cameo.time.time_zone/cameo.cameo.syslog_server can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

Affected products

  • TRENDnet Tew-821dap: version 2.2.01b05 only

Published 2026-08-22. Last modified 2026-08-26.