Junglewise Threat Intelligence

CVE-2026-10180: TRENDnet TEW-432BRP command injection in formSysCmd

CVE-2026-10180 · Severity: medium · CVSS 6.3 · Published 2026-05-31

Technologies: TRENDnet TEW-432BRP. Vendors: TRENDnet.

Executive brief

A command injection vulnerability exists in the TRENDnet TEW-432BRP wireless router, an older networking device used to provide internet connectivity. An attacker can exploit this flaw to take full control of the device, potentially leading to network disruptions or unauthorized access to traffic. Because this product reached its end-of-life in 2009, the manufacturer will not be providing a security patch, and users are advised to replace the hardware.

Technical details

A command injection vulnerability exists in the TRENDnet TEW-432BRP router (firmware version 3.10B20) within the 'formSysCmd' function of the '/goform/formSysCmd' endpoint. The 'sysCmd' parameter is passed directly to the underlying operating system without sufficient sanitization or validation. A remote attacker with low privileges (authenticated access) can exploit this by sending a specially crafted POST request to execute arbitrary shell commands on the device. The vendor has stated that no fix will be released as the product has been end-of-life (EOL) since 2009.

Affected products

  • TRENDnet TEW-432BRP 3.10B20

Timeline

  • 2009: other: Product reached End-of-Life (EOL) status
  • 2026-05-31: disclosed: Public disclosure of the vulnerability and PoC
  • 2026-05-31: advisory

References

Related threats