Junglewise Threat Intelligence

CVE-2026-10060: TRENDnet TEW-432BRP command injection in formSetRoute

CVE-2026-10060 · Severity: medium · CVSS 6.3 · Published 2026-05-29

Technologies: TRENDnet TEW-432BRP. Vendors: TRENDnet.

Executive brief

A vulnerability exists in the TRENDnet TEW-432BRP wireless router, a device used to provide internet connectivity for home and small office environments. An attacker can exploit this flaw to take control of the device by injecting malicious commands through the router's web management interface. Successful exploitation could lead to a complete service outage or unauthorized access to the network, though the manufacturer has stated they will not provide a fix as the product reached its end-of-life in 2009.

Technical details

A command injection vulnerability exists in the 'formSetRoute' function within the '/goform/formSetRoute' endpoint of the TRENDnet TEW-432BRP router (firmware version 3.10B20). The vulnerability is caused by improper neutralization of special elements in the 'ip', 'mask', and 'gateway' parameters, which are passed directly to the underlying operating system's shell. An authenticated attacker can exploit this by sending a specially crafted HTTP POST request containing shell metacharacters (e.g., backticks) to execute arbitrary commands with the privileges of the web server. The vendor has confirmed this product is End-of-Life (EOL) and no patch will be released.

Affected products

  • TRENDnet TEW-432BRP 3.10B20

Timeline

  • 2026-05-29: advisory: NVD publication date
  • 2009: other: Product reached End-of-Life (EOL) status

References

Related threats