Junglewise Threat Intelligence

CVE-2026-10121: TRENDnet TEW-432BRP stack overflow in formSetUrlFilter

CVE-2026-10121 · Severity: high · CVSS 8.8 · Published 2026-05-30

Technologies: TRENDnet TEW-432BRP. Vendors: TRENDnet.

Executive brief

A security vulnerability exists in the TRENDnet TEW-432BRP wireless router, a device used to provide internet connectivity for home and small office environments. An attacker can exploit this flaw to crash the router or potentially take full control of the device, leading to a complete loss of internet service and potential unauthorized access to the network. Because this product reached its end-of-life in 2009, the manufacturer will not be providing a security update, and users are advised to replace the hardware.

Technical details

A stack-based buffer overflow exists in the 'boa' binary of the TRENDnet TEW-432BRP router firmware version 3.10B20. The vulnerability is located within the 'formSetUrlFilter' function in the '/goform/formSetUrlFilter' component. The function fails to validate the length of the 'keyword_list' and 'keyword' parameters before copying them into a fixed-size stack buffer. A remote attacker with low privileges (authenticated access to the web interface) can exploit this by sending a specially crafted POST request, overwriting the return address to achieve arbitrary code execution or causing a device crash (DoS). No patch is available as the device is end-of-life (EOL).

Affected products

  • TRENDnet TEW-432BRP 3.10B20

Timeline

  • 2026-05-30: advisory: CVE-2026-10121 published by VulDB/NVD
  • 2009: other: Product reached End-of-Life (EOL) status

References

Related threats