Description
A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetProtocolFilter of the file /goform/formSetProtocolFilter. Such manipulation of the argument protocol_name leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-05-30
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The TEW-432BRP router contains a stack‑based buffer overflow in the formSetProtocolFilter handler located at /goform/formSetProtocolFilter. The flaw is triggered by manipulating the protocol_name argument and allows a remote attacker to overwrite stack data, potentially leading to arbitrary code execution. This weakness is classified as CWE-119 and CWE-121. An adversary could compromise the confidentiality, integrity, and availability of the device, and from there possibly pivot to other network assets.

Affected Systems

The vulnerability affects TRENDnet TEW‑432BRP units running firmware 3.10B20, which has been End‑Of‑Life since 2009. No patch or remediation is provided by the vendor because the product is no longer supported.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, but the exploit has been publicly disclosed and could be leveraged remotely through the router’s web interface. Because the device is no longer maintained, the risk of exploitation remains high while the likelihood of detection and mitigation is low. A remote attacker with network access to the device can trigger the overflow and take control of the router.

Generated by OpenCVE AI on May 30, 2026 at 16:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Block remote traffic to the /goform/formSetProtocolFilter endpoint or the entire device using firewall or ACL rules.
  • Replace the TRENDnet TEW‑432BRP with a supported, patched router from an active vendor.
  • Isolate the device on a separate network segment with strict ingress control and monitor logs for anomalous requests.
  • Deploy an IDS/IPS to flag attempts to hit the vulnerable endpoint and alert administrators.

Generated by OpenCVE AI on May 30, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 30 May 2026 15:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetProtocolFilter of the file /goform/formSetProtocolFilter. Such manipulation of the argument protocol_name leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Title TRENDnet TEW-432BRP formSetProtocolFilter stack-based overflow
First Time appeared Trendnet
Trendnet tew-432brp
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:a:trendnet:tew-432brp:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-432brp
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Trendnet Tew-432brp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-30T15:15:07.889Z

Reserved: 2026-05-29T17:19:26.741Z

Link: CVE-2026-10122

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-30T16:17:04.420

Modified: 2026-05-30T16:17:04.420

Link: CVE-2026-10122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-30T16:30:27Z

Weaknesses