CVE-2026-10060: TRENDnet TEW-432BRP formSetRoute command injection
A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument ip/mask/gateway leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10060?
The severity of CVE-2026-10060 is rated as medium with a score of 6.3.
How do I fix CVE-2026-10060?
To fix CVE-2026-10060, update the firmware of the TRENDnet TEW-432BRP to the latest version available from the manufacturer.
What type of vulnerability is CVE-2026-10060?
CVE-2026-10060 is classified as a command injection vulnerability.
Can CVE-2026-10060 be exploited remotely?
Yes, CVE-2026-10060 allows for remote exploitation of the affected device.
Which device is affected by CVE-2026-10060?
CVE-2026-10060 affects the TRENDnet TEW-432BRP model.