📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global phishing Cross-sector HIGH 10m Global data_breach Energy CRITICAL 1h Global phishing Government/Multi-sector HIGH 2h Global apt Education CRITICAL 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 5h Global vulnerability IT Infrastructure CRITICAL 6h Global vulnerability Technology and Software Development HIGH 7h Global vulnerability Enterprise IT and Government CRITICAL 7h Global ransomware Multiple Sectors / Enterprise CRITICAL 8h Global general Technology and Legal MEDIUM 8h Global phishing Cross-sector HIGH 10m Global data_breach Energy CRITICAL 1h Global phishing Government/Multi-sector HIGH 2h Global apt Education CRITICAL 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 5h Global vulnerability IT Infrastructure CRITICAL 6h Global vulnerability Technology and Software Development HIGH 7h Global vulnerability Enterprise IT and Government CRITICAL 7h Global ransomware Multiple Sectors / Enterprise CRITICAL 8h Global general Technology and Legal MEDIUM 8h Global phishing Cross-sector HIGH 10m Global data_breach Energy CRITICAL 1h Global phishing Government/Multi-sector HIGH 2h Global apt Education CRITICAL 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 5h Global vulnerability IT Infrastructure CRITICAL 6h Global vulnerability Technology and Software Development HIGH 7h Global vulnerability Enterprise IT and Government CRITICAL 7h Global ransomware Multiple Sectors / Enterprise CRITICAL 8h Global general Technology and Legal MEDIUM 8h
Vulnerabilities

CVE-2026-5355

Medium
A vulnerability has been found in Trendnet TEW-657BRM 1.00.1. Affected by this issue is the function vpn_drop of the file /setup.cgi. The manipulation of the argument policy_name leads to os command i
CWE-77 — Weakness Type
Published: Apr 2, 2026  ·  Modified: Apr 5, 2026  ·  Source: NVD
CVSS v3
6.3
🔗 NVD Official
📄 Description (English)

A vulnerability has been found in Trendnet TEW-657BRM 1.00.1. Affected by this issue is the function vpn_drop of the file /setup.cgi. The manipulation of the argument policy_name leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The vendor confirms, that "[t]he product in question (...) has been discontinued and end of life since June 23, 2011, that is more than 14 years ago. We no longer provide support for this product, so we are not able to confirm the vulnerabilities. We will make an announcement on our website's product support page and notify customers who registered their products with us." This vulnerability only affects products that are no longer supported by the maintainer.

🤖 AI Executive Summary

CVE-2026-5355 is a remote OS command injection vulnerability in the discontinued Trendnet TEW-657BRM router (end-of-life since 2011). The vulnerability exists in the /setup.cgi file's vpn_drop function through the policy_name parameter, allowing unauthenticated remote code execution. While the CVSS score is 6.3 (medium), the lack of vendor support and public exploit disclosure pose significant risks for legacy deployments still in use within Saudi organizations.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 18, 2026 15:18
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily affects Saudi organizations still operating legacy Trendnet TEW-657BRM routers, particularly in: (1) Small to medium-sized enterprises (SMEs) and government agencies with aging network infrastructure; (2) Telecom sector (STC, Mobily) if legacy equipment remains in remote offices or branch networks; (3) Healthcare facilities with outdated network equipment; (4) Educational institutions with legacy infrastructure. The impact is severe for affected organizations due to complete lack of vendor support and the ability to achieve unauthenticated remote code execution, potentially compromising entire network segments.
🏢 Affected Saudi Sectors
Telecommunications (STC, Mobily, Zain) Government Agencies Banking and Financial Services Healthcare Education Small and Medium Enterprises (SMEs)
⚖️ Saudi Risk Score (AI)
7.2
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Conduct urgent inventory of all Trendnet TEW-657BRM devices across the organization
2. Isolate any identified devices from production networks immediately
3. Implement network segmentation to restrict access to affected devices
4. Enable VPN access restrictions and disable remote management features

Patching Guidance:
- No patch is available from the vendor (product discontinued since 2011)
- Immediate replacement with supported, modern router models is mandatory
- Establish timeline for complete device replacement within 30 days

Compensating Controls:
1. Implement strict firewall rules blocking access to port 80/443 on affected devices
2. Deploy intrusion detection/prevention systems (IDS/IPS) to monitor for exploitation attempts
3. Restrict administrative access to affected devices to authorized personnel only
4. Disable VPN functionality if not actively required
5. Monitor for suspicious command patterns in logs

Detection Rules:
- Monitor HTTP requests to /setup.cgi with policy_name parameter containing shell metacharacters (|, ;, &, $, `, etc.)
- Alert on any successful command execution attempts on affected devices
- Track unauthorized access attempts to device management interfaces
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. إجراء جرد عاجل لجميع أجهزة Trendnet TEW-657BRM في المنظمة
2. عزل أي أجهزة محددة عن شبكات الإنتاج فوراً
3. تطبيق تقسيم الشبكة لتقييد الوصول إلى الأجهزة المتأثرة
4. تفعيل قيود الوصول إلى VPN وتعطيل ميزات الإدارة البعيدة

إرشادات التصحيح:
- لا يتوفر تصحيح من البائع (المنتج متوقف منذ عام 2011)
- الاستبدال الفوري بنماذج موجهات حديثة مدعومة إلزامي
- وضع جدول زمني لاستبدال الجهاز بالكامل خلال 30 يوماً

الضوابط البديلة:
1. تطبيق قواعد جدار الحماية الصارمة لحجب الوصول إلى المنافذ 80/443 على الأجهزة المتأثرة
2. نشر أنظمة كشف/منع الاختراق (IDS/IPS) لمراقبة محاولات الاستغلال
3. تقييد الوصول الإداري إلى الأجهزة المتأثرة للموظفين المصرح لهم فقط
4. تعطيل وظيفة VPN إذا لم تكن مطلوبة بنشاط
5. مراقبة أنماط الأوامر المريبة في السجلات

قواعد الكشف:
- مراقبة طلبات HTTP إلى /setup.cgi مع معامل policy_name يحتوي على أحرف shell (|، ;، &، $، `، إلخ)
- تنبيه عند أي محاولات تنفيذ أوامر ناجحة على الأجهزة المتأثرة
- تتبع محاولات الوصول غير المصرح بها إلى واجهات إدارة الجهاز
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.5.1.1 - Information security policies and procedures A.8.1.1 - User access management A.12.2.1 - Change management procedures A.12.6.1 - Management of technical vulnerabilities
🔵 SAMA CSF
ID.AM-2 - Asset management and inventory PR.DS-1 - Data security and protection PR.IP-1 - Security patch management DE.CM-8 - Vulnerability scanning and management
🟡 ISO 27001:2022
A.12.6.1 - Management of technical vulnerabilities A.14.2.1 - Change management A.8.1.1 - User access management A.5.1.1 - Information security policies
🟣 PCI DSS v4.0.1
Requirement 6.2 - Security patches and updates Requirement 11.2 - Vulnerability scanning
📊 CVSS Score
6.3
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityL — Low / Local
📋 Quick Facts
Severity Medium
CVSS Score6.3
CWECWE-77
EPSS0.30%
Exploit No
Patch ✗ No
Published 2026-04-02
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
7.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-77
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.