Description
A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. Affected is the function formPortFw of the file /goform/formPortFw. The manipulation of the argument server_name results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-05-31
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw lies in the formPortFw handler in the TEW-432BRP firmware, where the server_name argument is not properly validated, leading to a stack-based buffer overflow that can be triggered remotely. The overflow enables an attacker to overwrite return addresses and execute arbitrary code, potentially granting full control over the device. Such an attack can compromise confidentiality, integrity, and availability of the network managed by the router.

Affected Systems

The vulnerability affects TRENDnet TEW-432BRP routers running firmware version 3.10B20. This product has been end‑of‑life since 2009 and is no longer maintained or patched by the vendor.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity, but the EPSS score is not reported, leaving the exploitation probability unclear. The vulnerability is not listed in CISA KEV, yet a public exploit has been released. The likely attack vector is a remote HTTP request to the /goform/formPortFw endpoint with a malicious server_name parameter, which can be performed over the internet or an internal network if web management is reachable.

Generated by OpenCVE AI on May 31, 2026 at 02:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Replace the TRENDnet TEW-432BRP with a supported router or networking device that receives security updates.
  • Block or restrict external access to the /goform/formPortFw endpoint using firewall rules or access control lists, effectively disabling the vulnerable management interface.
  • If replacement is not immediately possible, configure the device to allow web management only from trusted internal IP addresses and monitor logs for suspicious activity.

Generated by OpenCVE AI on May 31, 2026 at 02:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 31 May 2026 01:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. Affected is the function formPortFw of the file /goform/formPortFw. The manipulation of the argument server_name results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Title TRENDnet TEW-432BRP formPortFw stack-based overflow
First Time appeared Trendnet
Trendnet tew-432brp
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:a:trendnet:tew-432brp:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-432brp
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Trendnet Tew-432brp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-31T00:45:08.477Z

Reserved: 2026-05-30T07:00:24.047Z

Link: CVE-2026-10158

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-31T02:16:34.107

Modified: 2026-05-31T02:16:34.107

Link: CVE-2026-10158

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-31T02:30:37Z

Weaknesses