Affected Vendors
- Cisco: 19 CVEs (8 critical)
- TRENDnet: 15 CVEs (11 critical)
- GL.iNet: 5 CVEs (all high)
- TP-Link: 3 CVEs
- Semtech, OpenWrt / DD-WRT, BEC: 1 CVE each
This week brings a significant security event: 45 new router and networking CVEs, with 16 rated critical and 15 rated high. Two vendors dominate the landscape—Cisco and TRENDnet—accounting for 34 of the 45 vulnerabilities. This is a high-volume week that requires immediate attention from network operations teams.
Critical Vulnerabilities: Cisco and TRENDnet Lead
Cisco dominates with 19 CVEs, 8 of which are critical. The most concerning are CVE-2026-20357, CVE-2026-20358, and CVE-2026-20030 (all CVSS 10.0), affecting Cisco Crosswork infrastructure. Additionally, CVE-2026-20315 and CVE-2026-20317 (CVSS 10.0) impact Cisco Secure Workload. These vulnerabilities stem from comprehensive internal security reviews conducted by Cisco's engineering teams. Administrators running Cisco Crosswork or Secure Workload solutions should prioritize patch availability checks immediately and plan update windows as patches become available.
TRENDnet follows with 15 CVEs, 11 critical. The most severe include CVE-2026-77946 (CVSS 10.0) affecting TEW-821DAP 2.2.01b05, which exploits unsafe NTP timezone configuration handling in /cgi-bin/apply_time.cgi. CVE-2026-75784 (CVSS 10.0) affects TEW-WLC100 1v2.07b01 via HTTP header manipulation in the nginx component. Stack-based buffer overflow vulnerabilities plague multiple models: CVE-2026-76589 and CVE-2026-76590 target TEW-755AP (up to 20260702), while CVE-2026-76584 affects TV-IP751WIC 11.03.03. Additional critical flaws include CVE-2026-75976 (TEW-823DRU, strcpy overflow) and CVE-2026-75877 (TV-IP751WIC, system callback vulnerabilities). If you operate any TRENDnet access points, IP cameras, or wireless controllers, firmware updates should be treated as urgent. Check TRENDnet's support portal for available patches for your specific model.
GL.iNet: Broad Multi-Model Impact
GL.iNet reported 5 high-severity vulnerabilities affecting numerous router models including A1300, AX1800, AXT1800, BE series (BE1400, BE3600, BE6500, BE9300, BE10000), MT series (MT2500, MT3000, MT3600BE, MT5000), and XE3000. CVE-2026-19983 and CVE-2026-19979 (both CVSS 8.3) have the broadest impact. Three additional vulnerabilities—CVE-2026-19982, CVE-2026-19980, and CVE-2026-19981 (CVSS 7.4 each)—affect firewall and configuration components. The widespread model coverage suggests a systemic issue in GL.iNet's 4.8.x firmware branch. Review your GL.iNet devices and prepare for imminent firmware updates.
Remaining Vendors
TP-Link reported 3 CVEs with unusual severity classifications. CVE-2026-17252 describes a stack-based buffer overflow in administrative login handling (CVSS 7.1), while CVE-2026-8619 is an unauthenticated denial-of-service affecting TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0, and Archer MR600 v2. CVE-2026-19683 involves DDNS credential exposure in Omada Gateways.
OpenWrt / DD-WRT users should note CVE-2026-62381 (CVSS 6.6), a heap-based buffer overflow in luci-lib-px5g's ASN.1 certificate signing routine. Semtech's CVE-2026-12520 (CVSS 6.4) affects Sierra Wireless HL7800 modem drivers.
Recommended Actions
- Cisco customers: Check Cisco Security Advisories for Crosswork and Secure Workload patches immediately
- TRENDnet administrators: Inventory all affected models (TEW-821DAP, TEW-WLC100, TEW-755AP, TV-IP751WIC, TEW-823DRU) and prioritize firmware updates
- GL.iNet users: Review your device roster and watch for 4.8.x+ firmware releases
- TP-Link operators: Isolate affected MR and Archer models from untrusted networks pending patches
- Patch planning: Stagger updates across your fleet to avoid service disruption, but treat all 16 critical CVEs as high-priority