PT-2026-29799 · Trendnet · Tew-657Brm+1

·

CVE-2026-5351

·

Published

2026-04-02

·

Updated

2026-04-02

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trendnet TEW-657BRM version 1.00.1
Description Remote OS command injection is possible via the add wps client function within the /setup.cgi file. This occurs when the wl enrolee pin argument is manipulated, allowing an attacker to execute arbitrary operating system commands remotely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5351

Affected Products

Tew-657Brm
Tew-657Brm Firmware