Impact
The TEW-432BRP router contains a stack‑based buffer overflow in the formSetProtocolFilter handler located at /goform/formSetProtocolFilter. The flaw is triggered by manipulating the protocol_name argument and allows a remote attacker to overwrite stack data, potentially leading to arbitrary code execution. This weakness is classified as CWE-119 and CWE-121. An adversary could compromise the confidentiality, integrity, and availability of the device, and from there possibly pivot to other network assets.
Affected Systems
The vulnerability affects TRENDnet TEW‑432BRP units running firmware 3.10B20, which has been End‑Of‑Life since 2009. No patch or remediation is provided by the vendor because the product is no longer supported.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, but the exploit has been publicly disclosed and could be leveraged remotely through the router’s web interface. Because the device is no longer maintained, the risk of exploitation remains high while the likelihood of detection and mitigation is low. A remote attacker with network access to the device can trigger the overflow and take control of the router.
OpenCVE Enrichment