Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.4

CVE-2026-15480: Trendnet TEW-635BRM: Remote Code Execution through Web Service

CVE-2026-15480 CVE-2026-15480
Summary

A vulnerability in an older version of Trendnet's TEW-635BRM router allows a hacker to execute code remotely, potentially taking control of the device. This affects devices that are no longer supported by the manufacturer, and users are advised to switch to newer devices. The manufacturer is not confirming the existence of the vulnerability, but recommends upgrading to a supported device.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
trendnet tew-635brm 1.00.03
Original title
A vulnerability was identified in Trendnet TEW-635BRM up to 1.00.03. This affects the function start_httpd of the file /sbin/rc of the component Web Service. Such manipulation of the argument devic...
Original description
A vulnerability was identified in Trendnet TEW-635BRM up to 1.00.03. This affects the function start_httpd of the file /sbin/rc of the component Web Service. Such manipulation of the argument device_name leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor explains: "We are unable to confirm if the vulnerability exists. This item has been EOL since 2011. We will make an official announcement of possible vulnerabilities, and recommend users to switch devices." This vulnerability only affects products that are no longer supported by the maintainer.
nvd CVSS2.0 9.0
nvd CVSS3.1 8.8
nvd CVSS4.0 7.4
Vulnerability type
CWE-119 Buffer Overflow
CWE-121 Stack-based Buffer Overflow
Published: 12 Jul 2026 · Updated: 20 Jul 2026 · First seen: 12 Jul 2026