CVE-2026-5353 identifies an OS command injection vulnerability in the `ping_test` function of the `/setup.cgi` file in the Trendnet TEW-657BRM 1.00.1 router, a product discontinued and unsupported since 2011. This Medium severity (CVSS 6.3) flaw allows remote attackers with low privileges to execute arbitrary commands without user interaction, potentially impacting confidentiality, integrity, and availability. An exploit for this vulnerability is publicly available, placing it on the "Hot List: Active," despite limited community discussion and no listed tools on major exploit intelligence platforms.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.00.1CPE matchmatch criteria | cpe:2.3:o:trendnet:tew-657brm_firmware:1.00.1:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.