Description
A flaw has been found in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formSetUrlFilter of the file /goform/formSetUrlFilter. This manipulation of the argument keyword_list/keyword causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-05-30
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the formSetUrlFilter function of the /goform/formSetUrlFilter endpoint. By manipulating the keyword_list parameter, an attacker can overflow the stack buffer. This overflow can corrupt adjacent memory, potentially allowing arbitrary code execution. The vulnerability is a classic stack-based overflow and could lead to compromise of the device and any network services it controls.

Affected Systems

The affected product is the TRENDnet TEW-432BRP 3.10B20 router. The device has been End‑of‑Life since 2009, and no vendor updates or patches are available for this firmware. All devices running this firmware are susceptible.

Risk and Exploitability

The CVSS score is 8.7, indicating a high severity. Because the device is exposed to the internet and the exploit has been published, it is possible to launch the attack remotely via standard web requests. EPSS is not available, but the lack of remediation and the critical CVSS indicate a high likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, but its severity warrants immediate attention.

Generated by OpenCVE AI on May 30, 2026 at 16:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Physically isolate the TEW-432BRP from the internal network or restrict its route to the internet using VLANs or firewall rules.
  • Block all inbound HTTP/HTTPS or web‑management traffic to the device by configuring upstream routers or firewalls to drop requests to its management IP address.
  • Replace the device with a supported, patched router or gateway that receives vendor updates and still provides necessary services.

Generated by OpenCVE AI on May 30, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 30 May 2026 15:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formSetUrlFilter of the file /goform/formSetUrlFilter. This manipulation of the argument keyword_list/keyword causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Title TRENDnet TEW-432BRP formSetUrlFilter stack-based overflow
First Time appeared Trendnet
Trendnet tew-432brp
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:a:trendnet:tew-432brp:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-432brp
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Trendnet Tew-432brp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-30T15:00:13.791Z

Reserved: 2026-05-29T17:19:24.327Z

Link: CVE-2026-10121

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-30T16:17:04.250

Modified: 2026-05-30T16:17:04.250

Link: CVE-2026-10121

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-30T16:30:27Z

Weaknesses