Junglewise Threat Intelligence

CVE-2026-10123: TRENDnet TEW-432BRP stack overflow in formSetDomainFilter

CVE-2026-10123 · Severity: high · CVSS 8.8 · Published 2026-05-30

Technologies: TRENDnet TEW-432BRP. Vendors: TRENDnet.

Executive brief

A vulnerability exists in the TRENDnet TEW-432BRP wireless router, a device used to provide internet connectivity and network security for small offices and homes. An attacker can exploit this flaw to crash the router or potentially take full control of the device by sending specially crafted web requests. Because this product reached its end-of-life in 2009, the manufacturer will not be releasing a security patch, and users are advised to replace the hardware.

Technical details

A stack-based buffer overflow vulnerability exists in the 'formSetDomainFilter' function within the '/goform/formSetDomainFilter' endpoint of the TRENDnet TEW-432BRP router (firmware 3.10B20). The issue stems from a lack of bounds checking when copying user-supplied input from parameters such as 'blocked_domain_list' into local stack variables. A remote attacker with low privileges (authenticated access to the web interface) can exploit this by sending an oversized string, leading to a crash of the 'boa' web server or arbitrary code execution. The vendor has stated that no fix will be provided as the product has been end-of-life (EOL) since 2009.

Affected products

  • TRENDnet TEW-432BRP 3.10B20

Timeline

  • 2026-05-30: disclosed: Vulnerability details and PoC published on GitHub.
  • 2026-05-30: advisory: CVE-2026-10123 published.

References

Related threats