Description
A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSysCmd of the file /goform/formSysCmd. Performing a manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-05-31
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack-based buffer overflow exists in the formSysCmd function of the TEW‑432BRP firmware, triggered by manipulating the submit-url parameter in a request to /goform/formSysCmd. The flaw allows a remote attacker to overflow a stack buffer and potentially execute arbitrary code, compromising confidentiality, integrity, and availability of the device. The vulnerability is classified by CWE‑119 and CWE‑121 as a classic buffer overflow with the potential for full control over the target. Public exploits have been released, indicating that an attacker can leverage this flaw without complex prerequisites.

Affected Systems

The vulnerability affects TRENDnet TEW‑432BRP routers running firmware version 3.10B20. This product has been EOL since 2009, and the vendor states they cannot reproduce or patch the flaw. As a result, any device still running this firmware remains vulnerable.

Risk and Exploitability

The CVSS score of 8.7 reflects a high severity level. Though the EPSS score is not available, the existence of a public exploit and the lack of vendor remediation place this flaw in a high-risk category. The attack can be initiated remotely by sending a crafted request from an external network, implying that exposure to the Internet or untrusted networks significantly raises the exploitation probability. Since TRENDnet has not provided a fix and the device is unsupported, the primary risk remains for organizations that continue to operate firmware 3.10B20 or an equivalent variant.

Generated by OpenCVE AI on May 31, 2026 at 14:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Ensure the device is not exposed to the Internet, removing or blocking external access to its management interfaces
  • Configure network segmentation and firewall rules to restrict HTTP and HTTPS traffic to the device from trusted networks only
  • Replace the EOL TEW‑432BRP router with a supported, security‑maintained replacement device

Generated by OpenCVE AI on May 31, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 31 May 2026 13:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSysCmd of the file /goform/formSysCmd. Performing a manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Title TRENDnet TEW-432BRP formSysCmd stack-based overflow
First Time appeared Trendnet
Trendnet tew-432brp
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:a:trendnet:tew-432brp:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-432brp
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Trendnet Tew-432brp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-31T12:45:07.166Z

Reserved: 2026-05-30T16:28:27.522Z

Link: CVE-2026-10181

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-31T13:16:48.407

Modified: 2026-05-31T13:16:48.407

Link: CVE-2026-10181

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-31T14:45:04Z

Weaknesses