Executive brief
A vulnerability exists in the TRENDnet TEW-432BRP wireless router, a legacy networking device. An attacker can exploit this flaw to crash the router or potentially take full control of the device by sending specially crafted network requests. Because this product reached its end-of-life in 2009, the manufacturer will not be releasing a security patch, leaving affected devices permanently vulnerable.
Technical details
A stack-based buffer overflow exists in the 'boa' binary of the TRENDnet TEW-432BRP router, specifically within the 'formSetRoute' function in '/goform/formSetRoute'. The vulnerability is caused by a lack of bounds checking on the 'ip', 'mask', and 'gateway' parameters, which are copied directly into local stack variables. A remote attacker with low privileges (authenticated access) can provide excessively long strings for these arguments to overwrite the function's return address. This can lead to a persistent denial of service (crash) or remote code execution. The vendor has confirmed this product is end-of-life (EOL) and no patch will be provided.
Affected products
- TRENDnet TEW-432BRP 3.10B20
Timeline
- 2009: other: Product reached End-of-Life (EOL) status
- 2026-05-29: advisory: Vulnerability publicly disclosed and CVE assigned