CVE-2026-76583
Deferred Deferred - Pending Action

Command Injection in TRENDnet TV-IP751WIC

Vulnerability report for CVE-2026-76583, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-20

Assigner: VulDB

Description

A vulnerability was identified in TRENDnet TV-IP751WIC 11.03.03. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The manipulation leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-20
Generated
2026-09-09
AI Q&A
2026-08-20
EPSS Evaluated
2026-09-07
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
trendnet tv-ip751wic 11.03.03

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a command injection flaw in TRENDnet TV-IP751WIC version 11.03.03. It exists in the /cgi-bin/admin/set_time.cgi file of the alphapd component. An attacker can remotely execute arbitrary commands on the affected device by manipulating input parameters.

Detection Guidance

To detect this vulnerability, scan your network for devices running TRENDnet TV-IP751WIC firmware version 11.03.03 or affected by the command injection flaw in /cgi-bin/admin/set_time.cgi. Use network scanning tools like Nmap to identify vulnerable devices by checking for open ports and services.

Impact Analysis

An attacker could gain unauthorized access to the device, execute malicious commands, steal sensitive data, or disrupt device operations. Since the exploit is publicly available, the risk of exploitation is higher. The impact depends on the device's role in your network.

Compliance Impact

This vulnerability allows remote command injection via /cgi-bin/admin/set_time.cgi, which could enable unauthorized access or data exfiltration. Such risks may impact compliance with GDPR (data protection) and HIPAA (health data security) by potentially exposing sensitive information or violating confidentiality requirements.

Mitigation Strategies

Immediately update the TRENDnet TV-IP751WIC firmware to the latest version. If an update is unavailable, isolate the device from your network to prevent remote exploitation. Disable remote access to the web interface and restrict access to trusted IPs only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76583. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart