Junglewise Threat Intelligence

CVE-2026-10061: TRENDnet TEW-432BRP command injection in formWPS

CVE-2026-10061 · Severity: medium · CVSS 6.3 · Published 2026-05-29

Technologies: TRENDnet TEW-432BRP. Vendors: TRENDnet.

Executive brief

A vulnerability exists in the TRENDnet TEW-432BRP wireless router, an older networking device used to provide internet connectivity. An attacker can remotely execute unauthorized commands on the router, potentially leading to a complete takeover of the device or a disruption of internet services. Because this product reached its end-of-life in 2009, the manufacturer will not be providing a security patch, and users are advised to replace the hardware.

Technical details

A command injection vulnerability exists in the 'formWPS' function within the '/goform/formWPS' component of the TRENDnet TEW-432BRP router (firmware version 3.10B20). The root cause is the improper neutralization of special elements in the 'peerPin' argument, which is passed directly to the underlying operating system without sufficient validation. A remote attacker with low privileges (authenticated access) can exploit this by sending a specially crafted POST request containing shell metacharacters (e.g., backticks) to execute arbitrary commands. The vendor has stated that no fix will be released as the product has been end-of-life (EOL) since 2009.

Affected products

  • TRENDnet TEW-432BRP 3.10B20

Timeline

  • 2026-05-29: advisory: NVD publication date
  • 2009: other: Product reached End-of-Life (EOL) status

References

Related threats