MEDIUM
TRENDnet TEW-755AP ssi email.cgi log_email_server command injection
Published Aug 19, 2026
5.3
MEDIUMCVSS 4.0
EPSS 1.82%
Description
A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function log_email_server of the file /cgi-bin/email.cgi of the component ssi. Performing a manipulation results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Affected products
-
- Version 20260702StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://github.com/meishigana/CVE/blob/main/team15_20260702/14_755ap-ssi-cmdi/poc/poc-ssi-injection.py exploit
- https://github.com/meishigana/CVE/tree/main/team15_20260702/14_755ap-ssi-cmdi related
- https://vuldb.com/cve/CVE-2026-76591 third-party-advisory
- https://vuldb.com/submit/877853 third-party-advisory
- https://vuldb.com/vuln/393088 vdb-entrytechnical-description
- https://vuldb.com/vuln/393088/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://github.com/meishigana/CVE/blob/main/team15_20260702/14_755ap-ssi-cmdi/poc/poc-ssi-injection.py | exploit | |
| https://github.com/meishigana/CVE/tree/main/team15_20260702/14_755ap-ssi-cmdi | related | |
| https://vuldb.com/cve/CVE-2026-76591 | third-party-advisory | |
| https://vuldb.com/submit/877853 | third-party-advisory | |
| https://vuldb.com/vuln/393088 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/393088/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Aug 19, 2026
Updated Aug 21, 2026
Reserved Aug 19, 2026
Link CVE-2026-76591
CISA Vulnrichment
Updated Aug 21, 2026