PatchSiren cyber security CVE debrief
CVE-2026-5350 Trendnet CVE debrief
A stack-based buffer overflow vulnerability exists in Trendnet TEW-657BRM 1.00.1, specifically in the update_pcdb function of /setup.cgi. The vulnerability is caused by manipulation of the mac_pc_dba argument. Trendnet has confirmed that the product has been discontinued and is no longer supported, having reached its end-of-life on June 23, 2011. Security teams should assess the use of this device and consider replacement, as vendor support is no longer available. The exploit has been publicly released, increasing the urgency for mitigation. Compensating controls and monitoring are recommended until a formal patch or advisory is provided, if at all.
- Vendor
- Trendnet
- Product
- TEW-657BRM
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-02
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-02
- Advisory updated
- 2026-07-24
Who should care
Security teams and administrators responsible for Trendnet TEW-657BRM devices, especially those still in use despite being discontinued and unsupported since June 23, 2011, should be aware of this vulnerability.
Technical summary
The CVE-2026-5350 vulnerability is a stack-based buffer overflow issue in the update_pcdb function of the /setup.cgi file in Trendnet TEW-657BRM version 1.00.1. The vulnerability is triggered by manipulating the mac_pc_dba argument. This issue allows for remote attacks, and an exploit has been publicly released. Trendnet has confirmed the product's discontinuation and end-of-life status, leading to a lack of support or confirmation of the vulnerability from the vendor.
Defensive priority
High priority should be given to identifying and mitigating this vulnerability in Trendnet TEW-657BRM devices still in use, despite their discontinued and unsupported status.
Recommended defensive actions
- Inventory and assess the use of Trendnet TEW-657BRM devices within your organization.
- Implement compensating controls to monitor and protect vulnerable devices.
- Consider replacing unsupported devices with supported alternatives.
- Monitor for and apply any future vendor advisories or patches, if unexpectedly provided.
- Restrict access to /setup.cgi and related functions.
Evidence notes
The CVE record was published on 2026-04-02T16:16:27.863Z and last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Analyzed. The vulnerability has a CVSS score of 7.4 and is classified as HIGH severity. The exploit has been released publicly and may be used for attacks.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-5350 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-5350
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-5350 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-5350
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/panda666-888/vuls/blob/main/trendnet/tew-657brm/update_pcdb.md
[email protected] - Exploit, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://vuldb.com/submit/781567
[email protected] - Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://vuldb.com/vuln/354703
[email protected] - Third Party Advisory, VDB Entry
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/354703/cti
[email protected] - Permissions Required, VDB Entry
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.