CVE-2026-10060

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument ip/mask/gateway leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
References
Link Resource
https://github.com/wudipjq/my_vuln/blob/main/TRENDnet/vuln_1/1.md Exploit Third Party Advisory
https://vuldb.com/submit/814756 Third Party Advisory VDB Entry
https://vuldb.com/vuln/367146 Third Party Advisory VDB Entry
https://vuldb.com/vuln/367146/cti Permissions Required VDB Entry
https://vuldb.com/submit/814756 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:trendnet:tew-432brp_firmware:3.10b20:*:*:*:*:*:*:*
cpe:2.3:h:trendnet:tew-432brp:-:*:*:*:*:*:*:*

History

21 Jul 2026, 12:10

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad en TRENDnet TEW-432BRP 3.10B20. Esto afecta la función formSetRoute del archivo /goform/formSetRoute. La manipulación del argumento ip/mask/gateway conduce a una inyección de comandos. La explotación remota del ataque es posible. El exploit ha sido divulgado al público y puede ser utilizado. El proveedor explica: 'Este producto ha estado EOL durante 15 años (desde 2009). Dado que el artículo ha estado EOL durante tanto tiempo, no podemos replicar ni solucionar ninguna vulnerabilidad.' Esta vulnerabilidad solo afecta a productos que ya no son compatibles con el mantenedor.

03 Jun 2026, 14:39

Type Values Removed Values Added
CPE cpe:2.3:h:trendnet:tew-432brp:-:*:*:*:*:*:*:*
cpe:2.3:o:trendnet:tew-432brp_firmware:3.10b20:*:*:*:*:*:*:*
First Time Trendnet tew-432brp
Trendnet
Trendnet tew-432brp Firmware
References () https://github.com/wudipjq/my_vuln/blob/main/TRENDnet/vuln_1/1.md - () https://github.com/wudipjq/my_vuln/blob/main/TRENDnet/vuln_1/1.md - Exploit, Third Party Advisory
References () https://vuldb.com/submit/814756 - () https://vuldb.com/submit/814756 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/367146 - () https://vuldb.com/vuln/367146 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/367146/cti - () https://vuldb.com/vuln/367146/cti - Permissions Required, VDB Entry

29 May 2026, 16:16

Type Values Removed Values Added
References () https://vuldb.com/submit/814756 - () https://vuldb.com/submit/814756 -

29 May 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 14:16

Updated : 2026-07-21 12:10


NVD link : CVE-2026-10060

Mitre link : CVE-2026-10060

CVE.ORG link : CVE-2026-10060


JSON object : View

Products Affected

trendnet

  • tew-432brp
  • tew-432brp_firmware
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')