Description
A flaw has been found in TRENDnet TEW-432BRP 3.10B20. This vulnerability affects the function formSetPassword of the file /goform/formSetPassword. Executing a manipulation of the argument webpage can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-05-31
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer overflow exists in the formSetPassword function of the TRENDnet TEW-432BRP 3.10B20 firmware. Manipulating the webpage argument can overwrite the stack, allowing an attacker to inject code or alter the device’s execution flow. The flaw is categorized as CWE‑119 and CWE‑121, indicating an improper input validation and unsafe stack handling. The vulnerability could compromise the confidentiality, integrity, and availability of the device if exploited.

Affected Systems

TRENDnet TEW‑432BRP devices running firmware 3.10B20 are affected. No other versions are listed in the current data.

Risk and Exploitability

The CVSS score of 8.7 reflects high severity, and the exploit is publicly available, indicating that remote attackers can trigger the overflow by sending a crafted webpage request to /goform/formSetPassword. The device has been end‑of‑life since 2009, so no vendor patch exists; the vulnerability remains exploitable. With no listing in CISA’s KEV catalog, the exploit risk relies on general remote attack factors rather than confirmed widespread attacks. In absence of a fix, the primary attack vector is a remote web interface request from an external network.

Generated by OpenCVE AI on May 31, 2026 at 03:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Configure network firewall rules to block all external access to the TEW‑432BRP’s web interface.
  • Limit the web interface to a trusted management network and enforce strict IP whitelisting.
  • Replace the TEW‑432BRP with a supported, actively maintained Wi‑Fi access point to eliminate the vulnerability.

Generated by OpenCVE AI on May 31, 2026 at 03:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 31 May 2026 02:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in TRENDnet TEW-432BRP 3.10B20. This vulnerability affects the function formSetPassword of the file /goform/formSetPassword. Executing a manipulation of the argument webpage can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Title TRENDnet TEW-432BRP formSetPassword stack-based overflow
First Time appeared Trendnet
Trendnet tew-432brp
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:a:trendnet:tew-432brp:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-432brp
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Trendnet Tew-432brp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-31T02:00:12.314Z

Reserved: 2026-05-30T07:00:34.588Z

Link: CVE-2026-10162

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-31T03:16:15.660

Modified: 2026-05-31T03:16:15.660

Link: CVE-2026-10162

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-31T03:30:05Z

Weaknesses