CVE-2026-10180: TRENDnet TEW-432BRP formSysCmd command injection
A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSysCmd of the file /goform/formSysCmd. Such manipulation of the argument sysCmd leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10180?
The severity of CVE-2026-10180 is rated as medium with a score of 6.3.
How do I fix CVE-2026-10180?
To fix CVE-2026-10180, ensure to update the TRENDnet TEW-432BRP firmware to the latest version provided by the manufacturer.
What type of vulnerability is CVE-2026-10180?
CVE-2026-10180 is a command injection vulnerability affecting the formSysCmd function of the TRENDnet TEW-432BRP.
Can CVE-2026-10180 be exploited remotely?
Yes, CVE-2026-10180 can be exploited remotely due to the nature of the command injection vulnerability.
What are the potential impacts of CVE-2026-10180?
The potential impacts of CVE-2026-10180 include unauthorized command execution, which could compromise the affected system's integrity and availability.