TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, exploitable via the HTTP parameters "command", "todo", and "next_file," which allows an attacker to execute arbitrary commands with root privileges.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/WhereisRain/TEW-657BRM |
|
History
Thu, 27 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Trendnet
Trendnet tew-657brm |
|
| Vendors & Products |
Trendnet
Trendnet tew-657brm |
Wed, 26 Nov 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, exploitable via the HTTP parameters "command", "todo", and "next_file," which allows an attacker to execute arbitrary commands with root privileges. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-26T20:45:42.139Z
Reserved: 2025-11-18T00:00:00.000Z
Link: CVE-2025-65202
No data.
Status : Received
Published: 2025-11-26T21:15:46.533
Modified: 2025-11-26T21:15:46.533
Link: CVE-2025-65202
No data.