Impact
The flaw resides in the formSetUrlFilter function of the /goform/formSetUrlFilter endpoint. By manipulating the keyword_list parameter, an attacker can overflow the stack buffer. This overflow can corrupt adjacent memory, potentially allowing arbitrary code execution. The vulnerability is a classic stack-based overflow and could lead to compromise of the device and any network services it controls.
Affected Systems
The affected product is the TRENDnet TEW-432BRP 3.10B20 router. The device has been End‑of‑Life since 2009, and no vendor updates or patches are available for this firmware. All devices running this firmware are susceptible.
Risk and Exploitability
The CVSS score is 8.7, indicating a high severity. Because the device is exposed to the internet and the exploit has been published, it is possible to launch the attack remotely via standard web requests. EPSS is not available, but the lack of remediation and the critical CVSS indicate a high likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, but its severity warrants immediate attention.
OpenCVE Enrichment