Executive brief
A security vulnerability has been identified in the Trendnet TEW-657BRM, a wireless router used for home and small office networking. An attacker could exploit this flaw to gain full control over the device, potentially leading to data interception or a complete service outage. However, the manufacturer has stated that this product reached its end-of-life in 2011 and will not receive a security patch.
Technical details
A stack-based buffer overflow exists in the 'add_apcdb' function within the '/setup.cgi' file of Trendnet TEW-657BRM firmware version 1.00.1. The vulnerability is caused by the improper use of the 'strcpy' function when processing the 'mac_pc_dba' HTTP POST parameter, which allows an attacker to overwrite the stack. A remote attacker with low privileges (authenticated) can exploit this by sending a specially crafted request to the device. Successful exploitation can lead to remote code execution (RCE) or a device crash. No patch is available as the product is end-of-life (EOL).
Affected products
- Trendnet TEW-657BRM 1.00.1
Timeline
- 2011-06-23: other: Product reached End-of-Life (EOL) status
- 2026-04-02: disclosed: Vulnerability publicly disclosed
- 2026-04-02: advisory: NVD advisory published