The CVSS 9.8 rating on CVE-2026-10061 is technically accurate but strategically misleading. This is a command injection flaw in the TRENDnet TEW-432BRP wireless router — a device that reached end-of-life in 2009, over fifteen years ago. TRENDnet has explicitly confirmed no patch will be released. There is no update mechanism, no vendor support pathway, and no firmware alternative. The vulnerability is real and severe in isolation, but the 'critical' severity label functions as a call to action that cannot be answered for this product.

What matters more than the headline score is what it obscures. The EPSS score of 0.0501 reflects a lower exploitation probability than the CVSS suggests — but even that metric doesn't capture the real exposure. A fifteen-year-old router at the network edge isn't an isolated device; it's potentially bridging to legacy systems that never got replaced because 'they still work.' The command injection in /goform/formWPS isn't just a foothold on one box — it's potentially a pivot into whatever that network segment was trusted to protect. Healthcare facilities, small businesses, and industrial sites running aging equipment often use these devices as their only perimeter.

The uncomfortable truth this CVE surfaces is the defender's information ratio. For actively maintained software, public disclosure helps defenders more than attackers because patches can be deployed faster than exploits are weaponized. For EOL hardware, that ratio inverts — defenders have no move, while attackers gain validated exploit tooling. The formalization of this vulnerability in the CVE database changes nothing technically, but it does shift the liability calculus: organizations with active TEW-432BRP deployments can no longer claim ignorance. They can only document their acceptance of a 9.8-rated command injection flaw.

Practical steps: Identify this device (and similar EOL hardware) in your asset inventory. If found, the response isn't patching — it's risk acceptance documentation, network segmentation review, and replacement planning. The CVE serves as a forcing function to surface forgotten infrastructure that drifted off asset management books years ago. That's the real service this disclosure provides, and it's more uncomfortable than 'patch this.'