Executive brief
A vulnerability exists in the Trendnet TEW-635BRM router, a device used to provide internet connectivity and networking for homes and small offices. An attacker can exploit this flaw to crash the router's web management interface or potentially take full control of the device. Because this product reached its end-of-life in 2011, the manufacturer is not providing a security patch, and users are advised to replace the hardware with a supported model.
Technical details
A stack-based buffer overflow exists in the 'start_httpd' function within the '/sbin/rc' binary of the Trendnet TEW-635BRM router (firmware v1.00.03). The vulnerability is caused by the unsafe use of 'strcpy()' when retrieving the 'device_name' and 'http_realm' NVRAM variables, which are copied into a fixed-size 126-byte stack buffer without length validation. An attacker with the ability to modify NVRAM settings (e.g., via the web interface) can provide a payload exceeding 136 bytes to overwrite the saved return address ($ra). This can lead to a crash of the mini_httpd service or remote code execution (RCE). The vendor has stated the device is EOL and will not be patched.
Affected products
- Trendnet TEW-635BRM 1.00.03
Timeline
- 2011: other: Product reached End-of-Life (EOL) status
- 2026-07-12: disclosed: Vulnerability details and PoC published
- 2026-07-12: advisory: CVE-2026-15480 published