CVE-2026-5355 describes an OS command injection vulnerability in the Trendnet TEW-657BRM router (firmware 1.00.1), allowing remote attackers to execute arbitrary commands via the 'vpn_drop' function in /setup.cgi. This flaw affects a product that has been discontinued and unsupported by the vendor since 2011. Rated Medium with a CVSS score of 6.3, the vulnerability is remotely exploitable with low complexity and low privileges, potentially impacting confidentiality, integrity, and availability. Although the exploit has been publicly disclosed, there is no evidence of active exploitation in the wild, nor are there readily available exploit modules in common frameworks. Community attention and media coverage surrounding this CVE are currently very low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.00.1CPE matchmatch criteria | cpe:2.3:o:trendnet:tew-657brm_firmware:1.00.1:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.