Impact
The flaw resides in the ipoa_test function of the /sbin/rc script in Trendnet TEW-635BRM firmware versions up to 1.00.03. By manipulating the ipoa_ipaddr argument, an attacker can inject arbitrary shell commands, leading to full compromise of the router. The vulnerability is catalogued as CWE-74 and CWE-77 and carries a CVSS score of 8.7, indicating high severity. A publicly available exploit has already been released, confirming that the attack can be carried out from outside the device’s local network.
Affected Systems
Trendnet TEW-635BRM routers running firmware 1.00.03 or earlier are affected. The product line has been End-of-Life since 2011 and the vendor has issued no patch; only replacement of the device offers a guaranteed fix.
Risk and Exploitability
The EPSS score of 2% suggests a low likelihood of widespread active exploitation, yet the public exploit code and the device’s remote accessibility mean an adversary could target it from any network that reaches the router. The CVSS score of 8.7 reflects the potential for complete control, and the device’s EOL status removes any possibility of vendor support. Although the vulnerability is not listed in the CISA KEV, the presence of exploit code elevates the risk profile for operators who continue to use the device.
OpenCVE Enrichment