CVE-2026-10182

A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formWlanSetup of the file /goform/formWlanSetup. Executing a manipulation of the argument enrollee can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Configurations

No configuration.

History

22 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) Se determinó una vulnerabilidad en TRENDnet TEW-432BRP 3.10B20. El elemento afectado es la función formWlanSetup del archivo /goform/formWlanSetup. La ejecución de una manipulación del argumento enrollee puede llevar a una inyección de comandos. El ataque puede lanzarse remotamente. El exploit ha sido divulgado públicamente y puede ser utilizado. El proveedor explica: 'Este producto ha estado EOL durante 15 años (desde 2009). Dado que el artículo ha estado EOL durante tanto tiempo, no podemos replicar ni solucionar ninguna vulnerabilidad.' Esta vulnerabilidad solo afecta a productos que ya no tienen soporte por parte del mantenedor.

31 May 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-31 14:16

Updated : 2026-07-22 07:10


NVD link : CVE-2026-10182

Mitre link : CVE-2026-10182

CVE.ORG link : CVE-2026-10182


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')