Junglewise Threat Intelligence

CVE-2026-5349: Trendnet TEW-657BRM stack overflow in setup.cgi

CVE-2026-5349 · Severity: high · CVSS 8.8 · Published 2026-04-02

Technologies: TRENDnet Tew-657brm, TRENDnet Tew-657brm Firmware. Vendors: TRENDnet.

Executive brief

A security vulnerability has been identified in the Trendnet TEW-657BRM, a wireless router used for home and small office networking. An attacker could exploit this flaw to gain full control over the device, potentially leading to data interception or a complete service outage. However, the manufacturer has stated that this product reached its end-of-life in 2011 and will not receive a security patch.

Technical details

A stack-based buffer overflow exists in the 'add_apcdb' function within the '/setup.cgi' file of Trendnet TEW-657BRM firmware version 1.00.1. The vulnerability is caused by the improper use of the 'strcpy' function when processing the 'mac_pc_dba' HTTP POST parameter, which allows an attacker to overwrite the stack. A remote attacker with low privileges (authenticated) can exploit this by sending a specially crafted request to the device. Successful exploitation can lead to remote code execution (RCE) or a device crash. No patch is available as the product is end-of-life (EOL).

Affected products

  • Trendnet TEW-657BRM 1.00.1

Timeline

  • 2011-06-23: other: Product reached End-of-Life (EOL) status
  • 2026-04-02: disclosed: Vulnerability publicly disclosed
  • 2026-04-02: advisory: NVD advisory published

References

Related threats