WRITEUP

WRITEUP WORKING POC
Exploit for CVE-2025-65202 - Trendnet Tew-657brm Firmware - OS Command Injection
AI Analysis

This repository contains a functional Python-based exploit for CVE-2025-65202, demonstrating an authenticated remote command injection vulnerability in Trendnet TEW-657BRM firmware via the setup.cgi binary. The PoC sends a crafted HTTP POST request with specific parameters to execute arbitrary commands with root privileges.

Attack Type
RCE
Complexity
trivial
Reliability
reliable
MITRE ATT&CK
T1203 - Exploitation for Client Execution T1190 - Exploit Public-Facing Application
Loading exploit code...
Download ZIP Password: eip
Source
Platform Writeup
Type poc
Files 1
Authors
yangchunyu
Vulnerability
CVE-2025-65202
Trendnet Tew-657brm Firmware - OS Command Injection
HIGH
CVSS 8.0