Executive brief
A security vulnerability exists in the TRENDnet TEW-432BRP wireless router, a device used to provide home and small office internet connectivity. An attacker can exploit this flaw to cause the router to crash or potentially take control of the device. Because this product reached its end-of-life in 2009, the manufacturer will not be releasing a fix, and users are advised to replace the hardware.
Technical details
A stack-based buffer overflow exists in the 'formSetPortTr' function within the '/goform/formSetPortTr' endpoint of the TRENDnet TEW-432BRP router (firmware 3.10B20). The vulnerability is caused by a lack of bounds checking on the 'special_name' POST parameter, which is copied directly into a local stack variable. A remote attacker with low privileges (authenticated access to the web interface) can provide an oversized string to overwrite the function's return address. This can lead to a persistent denial of service (device crash) or arbitrary code execution. The vendor has stated that no patch will be issued as the product has been end-of-life (EOL) since 2009.
Affected products
- TRENDnet TEW-432BRP 3.10B20
Timeline
- 2026-05-29: advisory: NVD publication date
- 2009: other: Product reached End-of-Life (EOL) status