CVE-2026-77946Critical· 10.0▾ MidnightA vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulatio…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 55 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 23.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
1.0%
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation of the argument system.ntp.server/system.ntp.enable_server/cameo.time.time_zone/cameo.cameo.syslog_server can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-90680Critical· 9.9A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207
CVE-2026-86514Medium· 6.3A weakness has been identified in vgmstream up to r2117
CVE-2026-86509Critical· 9.6A flaw has been found in D-Link DIR-895L A1_102b07
CVE-2026-86318Medium· 5.3A flaw has been found in java-json-tools json-patch up to 1.13
CVE-2026-86296Critical· 10.0A vulnerability was determined in D-Link DIR-822A A_101
CVE-2026-82478High· 7.3A vulnerability was determined in NASA Trick 19.6.0