Vulnerability Details CVE-2025-65202
TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, exploitable via the HTTP parameters "command", "todo", and "next_file," which allows an attacker to execute arbitrary commands with root privileges.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.9%
CVSS Severity
CVSS v3 Score 8.0
Products affected by CVE-2025-65202
-
cpe:2.3:h:trendnet:tew-657brm:-
-
cpe:2.3:o:trendnet:tew-657brm_firmware:1.00.1