Junglewise Threat Intelligence

CVE-2026-10158: TRENDnet TEW-432BRP stack overflow in formPortFw

CVE-2026-10158 · Severity: high · CVSS 8.8 · Published 2026-05-31

Technologies: TRENDnet TEW-432BRP. Vendors: TRENDnet.

Executive brief

A security vulnerability exists in the TRENDnet TEW-432BRP wireless router, a device used to provide internet connectivity in home and small office environments. An attacker can exploit this flaw to crash the router or potentially take full control of the device by sending a specially crafted request to the port forwarding configuration page. Because this product reached its end-of-life (EOL) status in 2009, the manufacturer will not be providing a security patch, leaving affected devices permanently vulnerable.

Technical details

A stack-based buffer overflow exists in the 'formPortFw' function within the '/goform/formPortFw' component of the TRENDnet TEW-432BRP firmware (version 3.10B20). The vulnerability is caused by a lack of bounds checking on the 'server_name' POST parameter before it is copied into a local stack buffer. A remote attacker with low privileges (authenticated access to the web interface) can exploit this by sending an overly long string, overwriting the function's return address to achieve arbitrary code execution or a device crash. Public exploit code (PoC) is available. The vendor has stated no fix will be released as the product has been EOL since 2009.

Affected products

  • TRENDnet TEW-432BRP 3.10B20

Timeline

  • 2026-05-31: advisory: NVD publication date
  • 2009: other: Product reached End-of-Life (EOL) status

References

Related threats