Description
A weakness has been identified in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSysLog of the file /goform/formSysLog. This manipulation of the argument current_page causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-05-31
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the formSysLog function of TRENDnet TEW‑432BRP firmware 3.10B20, where an attacker can supply a crafted current_page argument to overflow a stack buffer located at \/goform\/formSysLog. The unchecked buffer length allows overwriting of control data on the stack, which can lead to arbitrary code execution on the device. This stack‑based buffer overflow is associated with CWE‑119 and CWE‑121. Because the device has been End‑of‑Life for 15 years and the vendor cannot fix the flaw, any device running the 3.10B20 firmware remains exposed without an official patch.

Affected Systems

The only product affected is the TRENDnet TEW‑432BRP Wi‑Fi router that ships with firmware version 3.10B20. No newer firmware versions are documented as containing the fix; therefore, all units running 3.10B20 are vulnerable.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity exploitability. Although an EPSS score is not published, the publicly available exploit and the long unsupported status of the device make exploitation likely in the wild. The flaw is not listed in the CISA KEV catalog, but remote attackers can trigger the overflow by sending crafted HTTP requests to the /goform/formSysLog endpoint, and no patch is available to mitigate the risk.

Generated by OpenCVE AI on May 31, 2026 at 02:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Block network traffic to the /goform/formSysLog endpoint with firewall or ACL rules.
  • Isolate the device from untrusted networks, restricting management access to a dedicated VLAN or VPN tunnel.
  • Replace the TEW‑432BRP router with a supported device that receives ongoing security updates.

Generated by OpenCVE AI on May 31, 2026 at 02:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 31 May 2026 01:30:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSysLog of the file /goform/formSysLog. This manipulation of the argument current_page causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Title TRENDnet TEW-432BRP formSysLog stack-based overflow
First Time appeared Trendnet
Trendnet tew-432brp
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:a:trendnet:tew-432brp:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-432brp
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Trendnet Tew-432brp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-31T01:15:08.867Z

Reserved: 2026-05-30T07:00:26.542Z

Link: CVE-2026-10159

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-31T02:16:34.290

Modified: 2026-05-31T02:16:34.290

Link: CVE-2026-10159

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-31T03:30:05Z

Weaknesses