Junglewise Threat Intelligence

CVE-2026-10160: TRENDnet TEW-432BRP stack overflow in formSetEnableWizard

CVE-2026-10160 · Severity: high · CVSS 8.8 · Published 2026-05-31

Technologies: TRENDnet TEW-432BRP. Vendors: TRENDnet.

Executive brief

A security vulnerability exists in the TRENDnet TEW-432BRP wireless router, an older networking device used to provide internet connectivity. An attacker can exploit this flaw to crash the router or potentially take full control of the device. Because this product reached its end-of-life in 2009, the manufacturer will not be providing any security updates or fixes.

Technical details

A stack-based buffer overflow vulnerability exists in the 'formSetEnableWizard' function within the '/goform/formSetEnableWizard' endpoint of the TRENDnet TEW-432BRP router (firmware 3.10B20). The issue stems from a lack of bounds checking when copying the 'webpage' (or 'start_wizard') POST parameter into a local stack variable. A remote attacker with low privileges (authenticated access) can send a specially crafted HTTP POST request with an oversized string to overwrite the function's return address. This can lead to a device crash (DoS) or remote code execution. The vendor has stated that no patch will be released as the hardware has been end-of-life since 2009.

Affected products

  • TRENDnet TEW-432BRP 3.10B20

Timeline

  • 2026-05-31: advisory: NVD publication date
  • 2009: other: Product reached End-of-Life (EOL) status

References

Related threats