Impact
The vulnerability lies in the formSysLog function of TRENDnet TEW‑432BRP firmware 3.10B20, where an attacker can supply a crafted current_page argument to overflow a stack buffer located at \/goform\/formSysLog. The unchecked buffer length allows overwriting of control data on the stack, which can lead to arbitrary code execution on the device. This stack‑based buffer overflow is associated with CWE‑119 and CWE‑121. Because the device has been End‑of‑Life for 15 years and the vendor cannot fix the flaw, any device running the 3.10B20 firmware remains exposed without an official patch.
Affected Systems
The only product affected is the TRENDnet TEW‑432BRP Wi‑Fi router that ships with firmware version 3.10B20. No newer firmware versions are documented as containing the fix; therefore, all units running 3.10B20 are vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity exploitability. Although an EPSS score is not published, the publicly available exploit and the long unsupported status of the device make exploitation likely in the wild. The flaw is not listed in the CISA KEV catalog, but remote attackers can trigger the overflow by sending crafted HTTP requests to the /goform/formSysLog endpoint, and no patch is available to mitigate the risk.
OpenCVE Enrichment