CVE-2026-75784Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-08-19); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-08-18: 1Mentions · 2026-08-19: 3Mentions · 2026-08-23: 1Mentions · 2026-08-26: 1PoC Mentioned / Linked · 2026-08-19: 2PoC Mentioned / Linked · 2026-08-23: 1PoC Mentioned / Linked · 2026-08-26: 1Patch / Workaround · 2026-08-26: 1Technical Details · 2026-08-18: 1Technical Details · 2026-08-19: 2Technical Details · 2026-08-23: 1Technical Details · 2026-08-26: 108-1808-1908-2308-26
Signal classification4 categories
Disclosure
233.3%
PoC
233.3%
General
116.7%
Patch
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-181
Disclosure1
2026-08-193
Disclosure1General1PoC1
2026-08-231
PoC1
2026-08-261
Patch1
Full discourse6 posts
  • SecAlerts@SecAlertsCo
    PoC

    📡 TRENDnet TEW-WLC100 has a critical stack overflow in nginx's HTTP Header Handler (FUN_0040da4c) — no auth needed, network-accessible, full C/I/A impact. PoC exists. CVE-2026-75784 #cybersecurity #ciso #vulnerabilities https://secalerts.co/vulnerability/CVE-2026-75784?utm_campaign=x https://t.co/I6aFrkhyvr

    Post summary

    A critical stack overflow (CVE‑2026‑75784) in Trendnet TEW‑WLC100’s Nginx HTTP Header Handler is disclosed with a PoC available and full C/I/A impact, but no evidence of active exploitation, patch, or debunking.

    01011103
    878 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-61241 CVE-2026-70880 CVE-2026-70921 CVE-2026-73343 CVE-2026-75784 ..🧵👇

    Post summary

    The post merely lists several CVEs without providing additional details, links, or actionable information.

    1100041
    35 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [CVE] CVE-2026-75784 [HIGH PRIORITY] #TRENDnet TEW-WLC100 HTTP Header nginx FUN_0040da4c stack-based overflow 🔗 https://exploitgrid.net/cve/CVE-2026-75784

    Post summary

    CVE-2026-75784 is identified as a stack‑based overflow affecting an nginx component in a TRENDnet device, marked high priority, with a PoC hosted on ExploitGrid.

    1000032
    35 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-75784 Stack-Based Buffer Overflow in TRENDnet TEW-WLC100 via HTTP Header Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-75784

    Post summary

    A newly reported stack‑based buffer overflow (CVE-2026-75784) in the TRENDnet TEW‑WLC100’s HTTP header handling has been disclosed, with technical details available via the provided link.

    00010108
    4.1K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-75784 (CVSS 10.0) - Stack-based buffer overflow in TRENDnet TEW-WLC100 v1[.]2[.]07b01. Remote exploit now PUBLIC. Patch immediately if affected. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/TNWVvfKZ9m

    Post summary

    CVE-2026-75784 is a critical stack‑based buffer overflow in TRENDnet devices; a public exploit is available and affected users are urged to patch immediately.

    0000034
    115 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🔐 🚨 TRENDnet TEW-WLC100 — CVSS 10.0 CRITICAL CVE-2026-75784: Unauthenticated stack overflow in nginx → https://threataft.com/articles/trendnet-tew-wlc100-cve-2026-75784 #cybersecurity #infosec #TRENDnet #WLC #NetworkSecurity #CVSS10 #NoPatch #ThreatIntel

    Post summary

    The post announces a critical CVE‑2026‑75784 vulnerability in Trendnet TEW‑WLC100, specifying an unauthenticated stack overflow in nginx and a CVSS 10.0 score, but does not provide an exploit, patch, or evidence of active exploitation.

    0000042
    37 followersView on X

Explore more