TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, exploitable via the HTTP parameters "command", "todo", and "next_file," which allows an attacker to execute arbitrary commands with root privileges.
| Software | From | Fixed in |
|---|---|---|
| trendnet / tew-657brm_firmware | 1.00.1 | 1.00.1.x |