CVE-2026-10061
Last modified
CVE-2026-10061 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. EPSS estimates a 5.01% chance of exploitation in the next 30 days.
Description
A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in command injection. The attack can be executed remotely. The exploit has been made public and could be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Trendnet | Tew-432brp Firmware | 3.10b20 |
References
- https://github.com/wudipjq/my_vuln/blob/main/TRENDnet/vuln_2/2.mdExploit, Third Party Advisory
- https://vuldb.com/submit/814757Third Party Advisory, VDB Entry
- https://vuldb.com/vuln/367147Third Party Advisory, VDB Entry
- https://vuldb.com/vuln/367147/ctiPermissions Required, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-10061?
How severe is CVE-2026-10061?
How do I fix CVE-2026-10061?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-100604ClawHub (openclaw/clawhub) contains an incorrect authorizati…5.4
- CVE-2026-100605Flowise through 3.1.4 contains missing route-level RBAC chec…7.1
- CVE-2026-100606Flowise through 3.1.4 (Enterprise/platform mode with SSO ena…7.7
- CVE-2026-100607Flowise through 3.1.4 resolves SSO and local-password users …7.7
- CVE-2026-100608Flowise through 3.1.4 does not enforce authorization on the …8.3
- CVE-2026-100609Flowise (npm packages `flowise` and `flowise-components`) th…6.8
- CVE-2026-100610Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id…7.5
- CVE-2026-100611Capgo (capgo.app backend, versions ≤ 12.261.0) improperly re…6.5
- CVE-2026-100612Capgo (capgo.app) through version 12.261.0 contains an incom…7.2
- CVE-2026-100613capgo.app is an over-the-air (OTA) update platform for Capac…5.3
- CVE-2026-100614Capgo before 12.244.1 contains a cross-tenant integrity vuln…8.8
- CVE-2026-100615Cap-go capgo.app before 12.267.1 fails to validate target AP…8.8
Are you affected by CVE-2026-10061?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
