Executive brief
A vulnerability exists in the Trendnet TEW-657BRM router, an older networking device used for internet connectivity. An attacker can remotely take full control of the device by sending a specially crafted request to its management interface. This could lead to a complete loss of privacy for network traffic or the device being used as a foothold for further attacks. Note that this product reached its end-of-life in 2011 and is no longer supported by the manufacturer.
Technical details
An OS command injection vulnerability exists in the Trendnet TEW-657BRM router running firmware version 1.00.1. The flaw is located within the vpn_drop function in the /setup.cgi component. The root cause is the improper neutralization of the 'policy_name' POST parameter before it is passed to a system command execution function. A remote attacker with low privileges (authenticated access to the web interface) can exploit this by injecting shell commands into the parameter, leading to arbitrary code execution with the privileges of the web server. A public proof-of-concept exists. The vendor has stated the product is end-of-life and will not receive a patch.
Affected products
- Trendnet TEW-657BRM 1.00.1
Timeline
- 2011-06-23: other: Product reached End-of-Life (EOL) status
- 2026-04-02: disclosed: Vulnerability disclosed and exploit made public
- 2026-04-02: advisory