Description
A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. This affects the function formResetStatistic of the file /goform/formResetStatistic. Performing a manipulation of the argument status_statistic results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-05-31
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack‑based buffer overflow exists in the formResetStatistic function of TRENDnet TEW‑432BRP 3.10B20 when the status_statistic argument is manipulated. The flaw is exploitable remotely through the device’s web interface and is publicly known, enabling attackers to potentially overwrite the stack and execute arbitrary code on the device. This vulnerability maps to CWE‑119 and CWE‑121 and carries a CVSS score of 8.7, indicating high severity.

Affected Systems

The device model TEW‑432BRP, specifically firmware 3.10B20 (and potentially earlier releases), is affected. TRENDnet no longer maintains this product, which has been end‑of‑life since 2009.

Risk and Exploitability

Because the vulnerability can be triggered with a remote request and the exploit is public, the risk is high. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the lack of a vendor patch and the remote attack vector make it a significant threat. Attackers can initiate the exploit from outside the local network by sending a crafted HTTP request to /goform/formResetStatistic. Given the stack overrun potential, successful exploitation could lead to full device compromise, data disclosure, or denial of service.

Generated by OpenCVE AI on May 31, 2026 at 03:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Identify all TEW‑432BRP units in the network and assess whether they are exposed to external traffic
  • Replace or physically disconnect the device from the network, or migrate to a supported replacement appliance
  • Configure network segmentation or firewall rules to block external access to the device’s management interface

Generated by OpenCVE AI on May 31, 2026 at 03:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 31 May 2026 02:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. This affects the function formResetStatistic of the file /goform/formResetStatistic. Performing a manipulation of the argument status_statistic results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Title TRENDnet TEW-432BRP formResetStatistic stack-based overflow
First Time appeared Trendnet
Trendnet tew-432brp
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:a:trendnet:tew-432brp:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-432brp
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Trendnet Tew-432brp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-31T01:45:07.861Z

Reserved: 2026-05-30T07:00:31.778Z

Link: CVE-2026-10161

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-31T03:16:15.503

Modified: 2026-05-31T03:16:15.503

Link: CVE-2026-10161

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-31T06:00:12Z

Weaknesses