CVE-2026-10061

A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in command injection. The attack can be executed remotely. The exploit has been made public and could be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
References
Link Resource
https://github.com/wudipjq/my_vuln/blob/main/TRENDnet/vuln_2/2.md Exploit Third Party Advisory
https://vuldb.com/submit/814757 Third Party Advisory VDB Entry
https://vuldb.com/vuln/367147 Third Party Advisory VDB Entry
https://vuldb.com/vuln/367147/cti Permissions Required VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:trendnet:tew-432brp_firmware:3.10b20:*:*:*:*:*:*:*
cpe:2.3:h:trendnet:tew-432brp:-:*:*:*:*:*:*:*

History

21 Jul 2026, 12:10

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en TRENDnet TEW-432BRP 3.10B20. Afectada es la función formWPS del archivo /goform/formWPS. La manipulación del argumento peerPin resulta en inyección de comandos. El ataque puede ser ejecutado remotamente. El exploit ha sido hecho público y podría ser usado. El proveedor explica: 'Este producto ha estado EOL durante 15 años (desde 2009). Dado que el artículo ha estado EOL durante tanto tiempo, no podemos replicar ni solucionar ninguna vulnerabilidad.' Esta vulnerabilidad solo afecta a productos que ya no son compatibles con el mantenedor.

03 Jun 2026, 14:36

Type Values Removed Values Added
References () https://github.com/wudipjq/my_vuln/blob/main/TRENDnet/vuln_2/2.md - () https://github.com/wudipjq/my_vuln/blob/main/TRENDnet/vuln_2/2.md - Exploit, Third Party Advisory
References () https://vuldb.com/submit/814757 - () https://vuldb.com/submit/814757 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/367147 - () https://vuldb.com/vuln/367147 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/367147/cti - () https://vuldb.com/vuln/367147/cti - Permissions Required, VDB Entry
First Time Trendnet tew-432brp
Trendnet
Trendnet tew-432brp Firmware
CPE cpe:2.3:h:trendnet:tew-432brp:-:*:*:*:*:*:*:*
cpe:2.3:o:trendnet:tew-432brp_firmware:3.10b20:*:*:*:*:*:*:*

29 May 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 14:16

Updated : 2026-07-21 12:10


NVD link : CVE-2026-10061

Mitre link : CVE-2026-10061

CVE.ORG link : CVE-2026-10061


JSON object : View

Products Affected

trendnet

  • tew-432brp
  • tew-432brp_firmware
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')