Impact
A stack-based buffer overflow exists in the start_httpd function of the Trendnet TEW-635BRM router’s web service. The flaw is triggered by manipulating the device_name argument sent to the rc script, which runs externally via the web interface. Because the overflow occurs on the stack, an attacker who can send crafted requests to the device over the network can trigger arbitrary code execution, allowing full compromise of the device. The vulnerability maps to CWE-119 and CWE-121, indicating unsafe buffer handling and stack corruption.
Affected Systems
Trendnet’s TEW-635BRM routers shipped with firmware versions up to 1.00.03 are affected. The product is out-of-support (EOL since 2011), and no vendor patch exists. Any deployment of these firmware versions is vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, classifying it as high severity, and an EPSS score of less than 1%, suggesting low current exploitation probability. Nonetheless, a publicly available exploit can be leveraged remotely via device’s web interface, and the device’s lack of support makes it a likely target for attackers seeking unpatched legacy hardware. Based on the description, the attack vector is remote over the device's web interface. The flaw is not listed in the CISA KEV catalog, but the combination of high severity, public exploit, and unsupported hardware elevates the risk for any connected environment.
OpenCVE Enrichment