CVE-2026-5354 identifies an OS command injection vulnerability in the Trendnet TEW-657BRM 1.00.1 router, allowing remote execution via manipulation of the policy_name argument in /setup.cgi. This Medium severity (CVSS 6.3) flaw affects a product that reached end-of-life in 2011 and is no longer supported by the vendor, requiring low privileges for exploitation. While an exploit has been published and the CVE is on a "Hot List," it is not listed in common exploit databases, and its EPSS score and community discussion are low, suggesting limited current threat activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.00.1CPE matchmatch criteria | cpe:2.3:o:trendnet:tew-657brm_firmware:1.00.1:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.