Junglewise Threat Intelligence

CVE-2026-15481: Trendnet TEW-635BRM command injection in IPoA WAN Setup

CVE-2026-15481 · Severity: high · CVSS 8.8 · Published 2026-07-12

Vendors: TRENDnet.

Executive brief

A security vulnerability exists in the Trendnet TEW-635BRM router, a device used for internet connectivity. An attacker can exploit this flaw to take complete control of the device by injecting malicious commands into the network configuration settings. Because this product reached its end-of-life in 2011, the manufacturer will not be providing a security update, and users are advised to replace the device with a supported model.

Technical details

A command injection vulnerability exists in the 'ipoa_test' function within the '/sbin/rc' binary of Trendnet TEW-635BRM routers (firmware v1.00.03). The vulnerability stems from the unsafe use of 'sprintf' to concatenate the 'ipoa_ipaddr' NVRAM variable into a shell command string, which is subsequently executed via 'system()'. An attacker with the ability to modify NVRAM—typically achieved by uploading a tampered configuration file via the web interface—can inject shell metacharacters to execute arbitrary commands with root privileges. The vendor has stated the device is EOL (End of Life) since 2011 and will not be patched.

Affected products

  • Trendnet TEW-635BRM 1.00.03

Timeline

  • 2011: other: Product reached End-of-Life (EOL) status
  • 2026-07-12: advisory: Vulnerability disclosed via NVD/VulDB

References

Related threats