Junglewise Threat Intelligence

CVE-2026-10182: TRENDnet TEW-432BRP command injection in formWlanSetup

CVE-2026-10182 · Severity: medium · CVSS 6.3 · Published 2026-05-31

Technologies: TRENDnet TEW-432BRP. Vendors: TRENDnet.

Executive brief

A vulnerability exists in the TRENDnet TEW-432BRP wireless router that allows an attacker to remotely take control of the device. By sending a specially crafted request to the router's configuration interface, an attacker can execute arbitrary system commands. This could lead to a complete loss of device availability or unauthorized access to the network. Because this product reached its end-of-life in 2009, the manufacturer will not be providing a security update.

Technical details

A remote command injection vulnerability exists in the TRENDnet TEW-432BRP router, specifically within the 'formWlanSetup' function of the '/goform/formWlanSetup' endpoint. The vulnerability is caused by the 'enrollee' argument being passed directly to a system shell without sufficient sanitization or validation. An unauthenticated remote attacker can exploit this by sending a POST request containing shell metacharacters (e.g., backticks) in the 'enrollee' parameter. Successful exploitation allows for arbitrary code execution on the underlying operating system. The vendor has stated that no patch will be released as the product has been End-of-Life (EOL) since 2009.

Affected products

  • TRENDnet TEW-432BRP 3.10B20

Timeline

  • 2026-05-31: disclosed: Public disclosure of the vulnerability and PoC
  • 2026-05-31: advisory

References

Related threats