Impact
The flaw lies in the formPortFw handler in the TEW-432BRP firmware, where the server_name argument is not properly validated, leading to a stack-based buffer overflow that can be triggered remotely. The overflow enables an attacker to overwrite return addresses and execute arbitrary code, potentially granting full control over the device. Such an attack can compromise confidentiality, integrity, and availability of the network managed by the router.
Affected Systems
The vulnerability affects TRENDnet TEW-432BRP routers running firmware version 3.10B20. This product has been end‑of‑life since 2009 and is no longer maintained or patched by the vendor.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity, but the EPSS score is not reported, leaving the exploitation probability unclear. The vulnerability is not listed in CISA KEV, yet a public exploit has been released. The likely attack vector is a remote HTTP request to the /goform/formPortFw endpoint with a malicious server_name parameter, which can be performed over the internet or an internal network if web management is reachable.
OpenCVE Enrichment