TRENDnet TEW-432BRP formSysCmd command injection
Published May 31, 2026
5.3
MEDIUMCVSS 4.0
EPSS 1.05%
Description
A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSysCmd of the file /goform/formSysCmd. Such manipulation of the argument sysCmd leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Affected products
-
- Version 3.10B20StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| TRENDnet | Tew-432brp | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33500 Advisory
- https://github.com/wudipjq/my_vuln/blob/main/TRENDnet/vuln_17/17.md exploit
- https://vuldb.com/cve/CVE-2026-10180 third-party-advisory
- https://vuldb.com/submit/814774 third-party-advisory
- https://vuldb.com/vuln/367461 vdb-entrytechnical-description
- https://vuldb.com/vuln/367461/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33500 | Advisory | |
| https://github.com/wudipjq/my_vuln/blob/main/TRENDnet/vuln_17/17.md | exploit | |
| https://vuldb.com/cve/CVE-2026-10180 | third-party-advisory | |
| https://vuldb.com/submit/814774 | third-party-advisory | |
| https://vuldb.com/vuln/367461 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/367461/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.