Impact
A stack‑based buffer overflow exists in the formResetStatistic function of TRENDnet TEW‑432BRP 3.10B20 when the status_statistic argument is manipulated. The flaw is exploitable remotely through the device’s web interface and is publicly known, enabling attackers to potentially overwrite the stack and execute arbitrary code on the device. This vulnerability maps to CWE‑119 and CWE‑121 and carries a CVSS score of 8.7, indicating high severity.
Affected Systems
The device model TEW‑432BRP, specifically firmware 3.10B20 (and potentially earlier releases), is affected. TRENDnet no longer maintains this product, which has been end‑of‑life since 2009.
Risk and Exploitability
Because the vulnerability can be triggered with a remote request and the exploit is public, the risk is high. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the lack of a vendor patch and the remote attack vector make it a significant threat. Attackers can initiate the exploit from outside the local network by sending a crafted HTTP request to /goform/formResetStatistic. Given the stack overrun potential, successful exploitation could lead to full device compromise, data disclosure, or denial of service.
OpenCVE Enrichment