CVE-2026-76589
High · CVSS 8.6Published 2026-08-19
CVSS
8.6
High
EPSS
—
exploit probability
Active Exploit
No
not yet listed
What is CVE-2026-76589?
A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.
CVSS Score Explained
CVSS 8.6 is High severity. Exploitation is likely straightforward and the impact is significant — data loss, privilege escalation, or remote code execution are common outcomes. Patch as soon as possible.
EPSS Exploitation Probability
No EPSS score yet — model needs more data on this CVE.
References & Patches
- PoChttps://github.com/meishigana/CVE/blob/main/team15_20260702/13_755ap-mycli-bof/poc/poc-mycli-overflow.py
- ›https://github.com/meishigana/CVE/tree/main/team15_20260702/13_755ap-mycli-bof
- ›https://vuldb.com/cve/CVE-2026-76589
- ›https://vuldb.com/submit/877845
- ›https://vuldb.com/vuln/393085
- ›https://vuldb.com/vuln/393085/cti
Track vulnerabilities for your stack
Tell us what tech you run — Node.js, Python, Java, nginx, whatever — and get a weekly email when new CVEs affect it.
Recent CVEs
- CVE-2026-76923Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service5.5
- CVE-2026-76924Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service5.5
- CVE-2026-76926BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service3.1
- CVE-2026-76927H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service4.7
- CVE-2026-76928X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service7.5
- CVE-2026-76929Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service4.7