Impact
The Edit feature of Trendnet TEW-657BRM’s /setup.cgi exposes a command‑line injection point where a crafted pcdb_list value is executed on the device’s operating system. This flaw permits attackers to run arbitrary commands on the router, potentially compromising the entire network segment that the router protects. The vulnerability is limited to the 1.00.1 firmware build of the exact model, and the device has been end‑of‑life for over fourteen years, so no vendor maintenance or patching is offered.
Affected Systems
Only the Trendnet TEW‑657BRM model running firmware version 1.00.1 is affected. No other models or firmware releases are listed in the CNA data or the common platform enumeration. Because the device is discontinued, it is unlikely to receive official fixes.
Risk and Exploitability
The CVSS score of 5.3 signals a moderate risk, while an EPSS of 4% indicates that exploitation is unlikely to appear among the general threat landscape. The vulnerability is not listed in the CISA KEV catalog. The attack requires remote access to the router’s web interface; any remaining units exposed to the Internet keep the window of opportunity open. In the absence of a vendor patch, the only defense is to remove the device or isolate it from external traffic.
OpenCVE Enrichment