Impact
The flaw resides in the vpn_connect handler of the /setup.cgi script on the Trendnet TEW‑657BRM router. By manipulating the policy_name argument, an attacker can inject and execute arbitrary OS commands on the device, thereby achieving remote code execution. The vulnerability is an OS command injection (CWE‑77, CWE‑78) that allows an adversary to compromise the router’s confidentiality, integrity, and availability over a remote connection.
Affected Systems
The device in question is the Trendnet TEW‑657BRM router running firmware version 1.00.1. This model was discontinued and reached end‑of‑life in 2011, and the vendor no longer provides support or updates for it.
Risk and Exploitability
The CVSS score of 5.3 classifies the issue as medium severity, while the EPSS score of 5% indicates a low‑to‑moderate likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, but published exploits exist, implying that an attacker can trigger the flaw remotely. Because the device is unsupported, patching is impossible, leaving the risk largely unmitigated unless the device is removed from or isolated within the network.
OpenCVE Enrichment