PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-5355 Trendnet CVE debrief

CVE-2026-5355 is an OS command injection vulnerability in Trendnet TEW-657BRM 1.00.1. The vulnerability affects the vpn_drop function in /setup.cgi and can be exploited remotely. The vendor has discontinued support for this product since June 23, 2011. Security teams should assess their inventory for affected products and consider compensating controls, as the vendor no longer provides support. The vulnerability has a CVSS score of 2.1, indicating a low severity vulnerability.

Vendor
Trendnet
Product
TEW-657BRM
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-02
Original CVE updated
2026-07-24
Advisory published
2026-04-02
Advisory updated
2026-07-24

Who should care

Security teams responsible for Trendnet TEW-657BRM devices should assess their inventory for affected products and consider compensating controls, as the vendor no longer provides support. Operators of affected devices should review the vulnerability details and plan for mitigations or updates. Vulnerability management teams should prioritize compensating controls for exposed systems.

Technical summary

The vulnerability is caused by improper handling of the policy_name argument in the vpn_drop function of /setup.cgi. This allows attackers to inject OS commands. The CVSS score is 2.1, indicating a low severity vulnerability. The affected product, Trendnet TEW-657BRM 1.00.1, is no longer supported by the vendor. Defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Defensive priority

Low priority due to the low CVSS score and discontinued support for the affected product. However, defenders should still assess their inventory and consider compensating controls.

Recommended defensive actions

  • Verify inventory for affected Trendnet TEW-657BRM devices
  • Implement compensating controls to mitigate potential attacks
  • Monitor for potential exploitation attempts
  • Consider replacing affected devices with supported alternatives
  • Review vendor guidance for discontinued products
  • Assess the operational impact of the vulnerability
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record was published on 2026-04-02T17:16:32.510Z and last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Analyzed. The vendor confirms that the product in question has been discontinued and end of life since June 23, 2011. The vendor no longer provides support for this product. The vulnerability only affects products that are no longer supported by the maintainer. The CVE record was created based on limited source detail, and defenders should verify the affected scope and severity with the vendor or other trusted sources.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-02T17:16:32.510Z and has not been modified since then. The NVD entry is currently Analyzed.