Impact
A stack-based buffer overflow exists in the formSysCmd function of the TEW‑432BRP firmware, triggered by manipulating the submit-url parameter in a request to /goform/formSysCmd. The flaw allows a remote attacker to overflow a stack buffer and potentially execute arbitrary code, compromising confidentiality, integrity, and availability of the device. The vulnerability is classified by CWE‑119 and CWE‑121 as a classic buffer overflow with the potential for full control over the target. Public exploits have been released, indicating that an attacker can leverage this flaw without complex prerequisites.
Affected Systems
The vulnerability affects TRENDnet TEW‑432BRP routers running firmware version 3.10B20. This product has been EOL since 2009, and the vendor states they cannot reproduce or patch the flaw. As a result, any device still running this firmware remains vulnerable.
Risk and Exploitability
The CVSS score of 8.7 reflects a high severity level. Though the EPSS score is not available, the existence of a public exploit and the lack of vendor remediation place this flaw in a high-risk category. The attack can be initiated remotely by sending a crafted request from an external network, implying that exposure to the Internet or untrusted networks significantly raises the exploitation probability. Since TRENDnet has not provided a fix and the device is unsupported, the primary risk remains for organizations that continue to operate firmware 3.10B20 or an equivalent variant.
OpenCVE Enrichment