Junglewise Threat Intelligence

CVE-2026-10120: TRENDnet TEW-432BRP stack overflow in formSetFirewallRule

CVE-2026-10120 · Severity: high · CVSS 8.8 · Published 2026-05-30

Technologies: TRENDnet TEW-432BRP. Vendors: TRENDnet.

Executive brief

A vulnerability exists in the TRENDnet TEW-432BRP wireless router, a device used to provide internet connectivity and network security for small offices and homes. An attacker can exploit this flaw to crash the router or potentially take full control of the device by sending a specially crafted request to the firewall configuration page. Because this product reached its end-of-life in 2009, the manufacturer will not be releasing a fix, leaving affected devices permanently vulnerable.

Technical details

A stack-based buffer overflow vulnerability exists in the 'boa' web server binary of the TRENDnet TEW-432BRP router (firmware version 3.10B20). The flaw is located within the 'formSetFirewallRule' function in the '/goform/formSetFirewallRule' handler. The 'firewall_name' POST parameter is copied into a local stack buffer without adequate bounds checking, allowing an attacker to overwrite the return address. While the attack requires network access and basic authentication, it can lead to arbitrary code execution or a persistent denial of service (device crash). The vendor has stated no patch will be issued as the product has been end-of-life (EOL) since 2009.

Affected products

  • TRENDnet TEW-432BRP 3.10B20

Timeline

  • 2009: other: Product reached End-of-Life (EOL) status
  • 2026-05-30: disclosed: Public disclosure of the vulnerability and PoC
  • 2026-05-30: advisory

References

Related threats