Executive brief
A security vulnerability exists in the Trendnet TEW-657BRM wireless router, an older networking device used for internet connectivity. An attacker could exploit this flaw to take control of the router and execute unauthorized commands. Because this product reached its end-of-life in 2011, the manufacturer will not be providing a security patch, and users are advised to replace the hardware.
Technical details
An OS command injection vulnerability exists in the Trendnet TEW-657BRM router firmware version 1.00.1. The flaw is located within the 'vpn_connect' function in the '/setup.cgi' component. The root cause is the improper neutralization of the 'policy_name' parameter before it is passed to a system shell execution function. A remote attacker with low privileges (authenticated) can exploit this by sending a specially crafted POST request to execute arbitrary commands on the underlying operating system. A public proof-of-concept exploit is available. The vendor has stated the product is end-of-life (EOL) and will not receive updates.
Affected products
- Trendnet TEW-657BRM 1.00.1
Timeline
- 2011-06-23: other: Product reached End-of-Life (EOL) status
- 2026-04-02: disclosed: Vulnerability details and PoC published
- 2026-04-02: advisory