Junglewise Threat Intelligence

CVE-2026-5353: Trendnet TEW-657BRM command injection in setup.cgi

CVE-2026-5353 · Severity: medium · CVSS 6.3 · Published 2026-04-02

Technologies: TRENDnet Tew-657brm, TRENDnet Tew-657brm Firmware. Vendors: TRENDnet.

Executive brief

A security vulnerability exists in the Trendnet TEW-657BRM wireless router, a device used to provide internet connectivity and networking for homes or small offices. An attacker can exploit this flaw to take control of the device by injecting malicious commands through the diagnostic ping interface. Successful exploitation could lead to unauthorized access to the network, data interception, or a complete loss of internet service. This product is end-of-life and no longer receives security updates.

Technical details

An OS command injection vulnerability exists in the Trendnet TEW-657BRM router running firmware version 1.00.1. The flaw is located within the 'ping_test' function in the '/setup.cgi' component, where the 'c4_IPAddr' parameter is passed to the 'myPipe' function without adequate sanitization or validation. A remote attacker with low privileges (authenticated access) can exploit this by sending a specially crafted POST request to execute arbitrary system commands on the underlying operating system. While a public exploit exists, the vendor has stated the product reached end-of-life (EOL) in 2011 and will not be patched.

Affected products

  • Trendnet TEW-657BRM 1.00.1

Timeline

  • 2011-06-23: other: Product reached End-of-Life (EOL) status
  • 2026-04-02: disclosed: Vulnerability details and PoC made public
  • 2026-04-02: advisory

References

Related threats