CVE-2026-76591
published 2026-08-19CVE-2026-76591: A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function log_email_server of the file /cgi-bin/email.cgi of the…
PriorityP260high7.4CVSS 3.1
AVNACLPRLUINSCCLILAL
EPSS
1.82%
77.9th percentile
A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function log_email_server of the file /cgi-bin/email.cgi of the component ssi. Performing a manipulation results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| trendnet | tew-755ap | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
TRENDnet TEW-755AP up to 20260702 ssi /cgi-bin/email.cgi log_email_server command injection
vuldb·2026-08-23·CVSS 7.4
CVE-2026-76591 [HIGH] TRENDnet TEW-755AP up to 20260702 ssi /cgi-bin/email.cgi log_email_server command injection
A vulnerability identified as critical has been detected in TRENDnet TEW-755AP up to 20260702. This affects the function log_email_server of the file /cgi-bin/email.cgi of the component ssi. Performing a manipulation results in command injection.
This vulnerability is reported as CVE-2026-76591. The attack is possible to be carried out remotely. Moreover, an exploit is present.
GHSA
A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702.
ghsa_unreviewed·2026-08-20
CVE-2026-76591 [LOW] CWE-74 A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702.
A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function log_email_server of the file /cgi-bin/email.cgi of the component ssi. Performing a manipulation results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/meishigana/CVE/blob/main/team15_20260702/14_755ap-ssi-cmdi/poc/poc-ssi-injection.pyhttps://github.com/meishigana/CVE/tree/main/team15_20260702/14_755ap-ssi-cmdihttps://vuldb.com/cve/CVE-2026-76591https://vuldb.com/submit/877853https://vuldb.com/vuln/393088https://vuldb.com/vuln/393088/cti
2026-08-19
Published