Description
A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetDomainFilter of the file /goform/formSetDomainFilter. Performing a manipulation of the argument blocked_domain/permitted_domain/blocked_domain_list/permitted_domain_list results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-05-30
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a stack-based buffer overflow in the formSetDomainFilter function, triggered by passing oversized parameters in blocked_domain, permitted_domain, blocked_domain_list, or permitted_domain_list to the /goform/formSetDomainFilter endpoint. A remote attacker can exploit the overflow to overwrite critical control data on the stack, allowing arbitrary code execution to run with the privileges of the device. The vulnerability is implicit in the software’s input handling, classed as CWE‑119 and CWE‑121.

Affected Systems

The affected equipment is the TRENDnet TEW‑432BRP Wi‑Fi access point, running firmware 3.10B20. This model has been officially obsolete since 2009, so the vendor no longer maintains or supplies security updates for this product.

Risk and Exploitability

The severity score of 8.7 reflects a high‑risk exploitation scenario. With no EPSS data available and the vulnerability not catalogued in the CISA KEV list, the public nature of the exploit and remote attack vector still present a significant threat. Since the device lacks an up‑to‑date patch, the likelihood of a successful attack remains high if the device is exposed to untrusted networks.

Generated by OpenCVE AI on May 30, 2026 at 17:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disconnect the TEW‑432BRP from all operational networks or block inbound management traffic with a firewall guard zone
  • Replace the obsolete access point with a currently supported model that receives security patches
  • If replacement is infeasible, enforce strict network segmentation and access control to limit exposure of the device’s management interface

Generated by OpenCVE AI on May 30, 2026 at 17:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 30 May 2026 16:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetDomainFilter of the file /goform/formSetDomainFilter. Performing a manipulation of the argument blocked_domain/permitted_domain/blocked_domain_list/permitted_domain_list results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Title TRENDnet TEW-432BRP formSetDomainFilter stack-based overflow
First Time appeared Trendnet
Trendnet tew-432brp
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:a:trendnet:tew-432brp:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-432brp
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Trendnet Tew-432brp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-30T15:30:09.461Z

Reserved: 2026-05-29T17:19:29.210Z

Link: CVE-2026-10123

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-30T16:17:04.580

Modified: 2026-05-30T16:17:04.580

Link: CVE-2026-10123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-30T18:00:12Z

Weaknesses