Aller au contenu

Fiche vulnérabilité

CVE-2026-10061 : faille critique trendnet tew-432brp firmware (CVSS 9.8)

Description

A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in command injection. The attack can be executed remotely. The exploit has been made public and could be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
29 mai 2026
Dernière mise à jour
21 juil. 2026

Produits concernés

  • trendnet tew-432brp firmware

Références

Rechercher une autre vulnérabilité dans la base CVE