Executive brief
A security vulnerability exists in the TRENDnet TEW-432BRP wireless router, a device used to provide internet connectivity and networking for home and small office environments. An attacker can exploit this flaw to crash the router or potentially take full control of the device by sending a specially crafted request to the MAC filtering configuration page. Because this product reached its end-of-life in 2009, the manufacturer will not be releasing a security patch, leaving affected devices permanently vulnerable.
Technical details
A stack-based buffer overflow vulnerability exists in the 'boa' web server binary of the TRENDnet TEW-432BRP router, specifically within the 'formSetMACFilter' function in '/goform/formSetMACFilter'. The vulnerability is caused by a lack of bounds checking on the 'filter_name' POST parameter, which is copied directly into a fixed-size local stack buffer. A remote attacker with low-privileged access (authenticated) can provide an overly long string to overwrite the function's return address, leading to a system crash (DoS) or arbitrary code execution. This product is end-of-life (EOL) and no patch is available.
Affected products
- TRENDnet TEW-432BRP 3.10B20
Timeline
- 2026-05-30: advisory: NVD publication date
- 2009: other: Product reached End-of-Life (EOL) status