Description
A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.03. This vulnerability affects the function ipoa_test of the file /sbin/rc of the component IPoA WAN Connection Setup. Performing a manipulation of the argument ipoa_ipaddr results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor explains: "We are unable to confirm if the vulnerability exists. This item has been EOL since 2011. We will make an official announcement of possible vulnerabilities, and recommend users to switch devices." This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-07-12
Score: 8.7 High
EPSS: 1.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the ipoa_test function of the /sbin/rc script in Trendnet TEW-635BRM firmware versions up to 1.00.03. By manipulating the ipoa_ipaddr argument, an attacker can inject arbitrary shell commands, leading to full compromise of the router. The vulnerability is catalogued as CWE-74 and CWE-77 and carries a CVSS score of 8.7, indicating high severity. A publicly available exploit has already been released, confirming that the attack can be carried out from outside the device’s local network.

Affected Systems

Trendnet TEW-635BRM routers running firmware 1.00.03 or earlier are affected. The product line has been End-of-Life since 2011 and the vendor has issued no patch; only replacement of the device offers a guaranteed fix.

Risk and Exploitability

The EPSS score of 2% suggests a low likelihood of widespread active exploitation, yet the public exploit code and the device’s remote accessibility mean an adversary could target it from any network that reaches the router. The CVSS score of 8.7 reflects the potential for complete control, and the device’s EOL status removes any possibility of vendor support. Although the vulnerability is not listed in the CISA KEV, the presence of exploit code elevates the risk profile for operators who continue to use the device.

Generated by OpenCVE AI on July 31, 2026 at 12:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Replace the Trendnet TEW-635BRM router with a supported, actively maintained device.
  • An immediate option is to block external access to the router’s administrative interface and enforce firewall or ACL rules that deny remote use of the ipoa_test command.
  • Continuously monitor system logs for abnormal activity or execution of the ipoa_test function and trigger alerts on any suspicious events.

Generated by OpenCVE AI on July 31, 2026 at 12:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 12 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.03. This vulnerability affects the function ipoa_test of the file /sbin/rc of the component IPoA WAN Connection Setup. Performing a manipulation of the argument ipoa_ipaddr results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor explains: "We are unable to confirm if the vulnerability exists. This item has been EOL since 2011. We will make an official announcement of possible vulnerabilities, and recommend users to switch devices." This vulnerability only affects products that are no longer supported by the maintainer.
Title Trendnet TEW-635BRM IPoA WAN Connection Setup rc ipoa_test command injection
First Time appeared Trendnet
Trendnet tew-635brm
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:trendnet:tew-635brm:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-635brm
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Trendnet Tew-635brm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-13T14:39:42.474Z

Reserved: 2026-07-11T10:02:32.426Z

Link: CVE-2026-15481

cve-icon Vulnrichment

Updated: 2026-07-13T14:39:35.427Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:45:03Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')