Impact
The flaw is a stack-based buffer overflow in the formSetDomainFilter function, triggered by passing oversized parameters in blocked_domain, permitted_domain, blocked_domain_list, or permitted_domain_list to the /goform/formSetDomainFilter endpoint. A remote attacker can exploit the overflow to overwrite critical control data on the stack, allowing arbitrary code execution to run with the privileges of the device. The vulnerability is implicit in the software’s input handling, classed as CWE‑119 and CWE‑121.
Affected Systems
The affected equipment is the TRENDnet TEW‑432BRP Wi‑Fi access point, running firmware 3.10B20. This model has been officially obsolete since 2009, so the vendor no longer maintains or supplies security updates for this product.
Risk and Exploitability
The severity score of 8.7 reflects a high‑risk exploitation scenario. With no EPSS data available and the vulnerability not catalogued in the CISA KEV list, the public nature of the exploit and remote attack vector still present a significant threat. Since the device lacks an up‑to‑date patch, the likelihood of a successful attack remains high if the device is exposed to untrusted networks.
OpenCVE Enrichment