Executive brief
A vulnerability exists in the TRENDnet TEW-432BRP wireless router, a device used to provide internet connectivity for home and small office environments. An attacker can exploit this flaw to crash the router or potentially take full control of the device by sending a specially crafted web request. Because this product reached its end-of-life in 2009, the manufacturer will not be providing a security update, leaving affected devices permanently vulnerable.
Technical details
A stack-based buffer overflow vulnerability exists in the 'boa' web server binary of the TRENDnet TEW-432BRP router (version 3.10B20). The flaw is located within the 'formSetProtocolFilter' function in the '/goform/formSetProtocolFilter' endpoint. The 'protocol_name' POST parameter is copied into a local stack variable without adequate bounds checking, allowing an attacker to overwrite the function's return address. Exploitation requires network access and low-level authentication (e.g., default credentials). Successful exploitation can lead to arbitrary code execution or a persistent denial of service (device crash). No patch is available as the device has been end-of-life (EOL) since 2009.
Affected products
- TRENDnet TEW-432BRP 3.10B20
Timeline
- 2026-05-30: disclosed: Public disclosure of the vulnerability and PoC.
- 2026-05-30: advisory: NVD published the CVE record.