Trendnet · Tew-821Dap · CVE-2026-77946
**Name of the Vulnerable Software and Affected Versions**
TRENDnet TEW-821DAP version 2.2.01b05
**Description**
A stack-based buffer overflow exists in the NTP Timezone Configuration Handler within the `uci safe get()` function of the `/cgi-bin/apply time.cgi` endpoint. This issue occurs because the function lacks adequate bounds checking when processing inputs, allowing a remote, unauthenticated attacker to overwrite stack data and execute arbitrary code. The flaw can be triggered by manipulating the `system.ntp.server`, `system.ntp.enable server`, `cameo.time.time zone`, or `cameo.cameo.syslog server` variables.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.