Impact
A buffer overflow exists in the formSetPassword function of the TRENDnet TEW-432BRP 3.10B20 firmware. Manipulating the webpage argument can overwrite the stack, allowing an attacker to inject code or alter the device’s execution flow. The flaw is categorized as CWE‑119 and CWE‑121, indicating an improper input validation and unsafe stack handling. The vulnerability could compromise the confidentiality, integrity, and availability of the device if exploited.
Affected Systems
TRENDnet TEW‑432BRP devices running firmware 3.10B20 are affected. No other versions are listed in the current data.
Risk and Exploitability
The CVSS score of 8.7 reflects high severity, and the exploit is publicly available, indicating that remote attackers can trigger the overflow by sending a crafted webpage request to /goform/formSetPassword. The device has been end‑of‑life since 2009, so no vendor patch exists; the vulnerability remains exploitable. With no listing in CISA’s KEV catalog, the exploit risk relies on general remote attack factors rather than confirmed widespread attacks. In absence of a fix, the primary attack vector is a remote web interface request from an external network.
OpenCVE Enrichment