Executive brief
A security vulnerability exists in the Trendnet TEW-657BRM wireless router, a device used to provide internet connectivity and networking for homes and small offices. An attacker can exploit this flaw to take control of the router's operating system, potentially leading to unauthorized access to network traffic or a complete service outage. This product reached its end-of-life in 2011 and is no longer supported by the manufacturer, meaning no official security updates will be released.
Technical details
An OS command injection vulnerability exists in the Trendnet TEW-657BRM router firmware version 1.00.1. The flaw is located within the 'add_wps_client' function in '/setup.cgi', where the 'wl_enrolee_pin' POST parameter is passed directly to a system shell call without sufficient sanitization. A remote attacker with low-level authentication can exploit this by sending a specially crafted HTTP request to execute arbitrary commands on the underlying Linux operating system. A public proof-of-concept exploit is available. The vendor has stated the product is end-of-life (EOL) as of June 2011 and will not receive a patch.
Affected products
- Trendnet TEW-657BRM 1.00.1
Timeline
- 2011-06-23: other: Product reached End-of-Life (EOL) status
- 2026-04-02: disclosed: Vulnerability disclosed and CVE assigned