Executive brief
A security vulnerability exists in the TRENDnet TEW-432BRP wireless router, a device used to provide internet connectivity for home and small office environments. An attacker can exploit this flaw to crash the router or potentially take full control of the device by sending a specially crafted request. Because this product reached its end-of-life in 2009, the manufacturer will not be releasing a fix, and users are advised to replace the hardware with a supported model.
Technical details
A stack-based buffer overflow vulnerability exists in the 'boa' binary of the TRENDnet TEW-432BRP router, specifically within the 'formWPS' function located at '/goform/formWPS'. The vulnerability is caused by a lack of bounds checking on the 'peerPin' POST parameter, which is copied directly into a local stack variable. A remote attacker with low privileges (authenticated access) can provide an excessively long string to overwrite the function's return address, leading to arbitrary code execution or a device crash (DoS). The vendor has stated that no patch will be issued as the product has been end-of-life (EOL) since 2009.
Affected products
- TRENDnet TEW-432BRP 3.10B20
Timeline
- 2026-05-29: disclosed
- 2026-05-29: advisory: NVD publication date