Junglewise Threat Intelligence

CVE-2026-5352: Trendnet TEW-657BRM OS command injection in setup.cgi

CVE-2026-5352 · Severity: medium · CVSS 6.3 · Published 2026-04-02

Technologies: TRENDnet Tew-657brm, TRENDnet Tew-657brm Firmware. Vendors: TRENDnet.

Executive brief

A security vulnerability exists in the Trendnet TEW-657BRM wireless router that allows an attacker to take control of the device. By sending a specially crafted request to the router's management interface, an attacker can execute unauthorized system commands. This could lead to a complete compromise of the device, interception of network traffic, or disruption of internet services. However, this product reached its end-of-life in 2011 and is no longer supported by the manufacturer.

Technical details

An OS command injection vulnerability exists in the Trendnet TEW-657BRM router firmware version 1.00.1. The 'Edit' function within the '/setup.cgi' script fails to properly sanitize the 'pcdb_list' parameter before passing it to a system shell (SYSTEM function). A remote attacker with low privileges (authenticated) can exploit this by sending a crafted POST request to execute arbitrary commands on the underlying operating system. The vendor has stated the product is end-of-life (EOL) as of June 2011 and will not be issuing a patch. A public exploit (PoC) is available.

Affected products

  • Trendnet TEW-657BRM 1.00.1

Timeline

  • 2011-06-23: other: Product reached End-of-Life (EOL) status
  • 2026-04-02: disclosed: Public disclosure of the vulnerability and exploit
  • 2026-04-02: advisory

References

Related threats