Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.4
CVE-2026-15481: Trendnet TEW-635BRM IPoA WAN Setup Allows Remote Attack
CVE-2026-15481
CVE-2026-15481
Summary
A security risk exists in older Trendnet TEW-635BRM routers. An attacker could potentially take control of the router from a distance, using a publicly available exploit. If you're still using this router, it's recommended to replace it with a newer, supported model.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| trendnet | tew-635brm | 1.00.03 |
Original title
A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.03. This vulnerability affects the function ipoa_test of the file /sbin/rc of the component IPoA WAN Connection Setup. Performi...
Original description
A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.03. This vulnerability affects the function ipoa_test of the file /sbin/rc of the component IPoA WAN Connection Setup. Performing a manipulation of the argument ipoa_ipaddr results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor explains: "We are unable to confirm if the vulnerability exists. This item has been EOL since 2011. We will make an official announcement of possible vulnerabilities, and recommend users to switch devices." This vulnerability only affects products that are no longer supported by the maintainer.
nvd CVSS2.0
9.0
nvd CVSS3.1
8.8
nvd CVSS4.0
7.4
Vulnerability type
CWE-74
Injection
CWE-77
Command Injection
Published: 12 Jul 2026 · Updated: 17 Jul 2026 · First seen: 12 Jul 2026