Junglewise Threat Intelligence

CVE-2026-10161: TRENDnet TEW-432BRP stack overflow in formResetStatistic

CVE-2026-10161 · Severity: high · CVSS 8.8 · Published 2026-05-31

Technologies: TRENDnet TEW-432BRP. Vendors: TRENDnet.

Executive brief

A security vulnerability exists in the TRENDnet TEW-432BRP wireless router, an older networking device used to provide internet connectivity. An attacker can exploit this flaw to crash the router or potentially take full control of the device, leading to a complete loss of internet service and potential access to internal network traffic. Because this product reached its end-of-life in 2009, the manufacturer will not be providing any security updates or fixes.

Technical details

A stack-based buffer overflow exists in the 'boa' binary of the TRENDnet TEW-432BRP router, specifically within the 'formResetStatistic' function in the '/goform/formResetStatistic' file. The vulnerability is caused by a lack of bounds checking on the 'status_statistic' (or 'webpage' as seen in PoC) parameter, which is copied directly into a local stack variable. A remote attacker with low privileges can exploit this by sending a specially crafted POST request with an oversized argument, overwriting the function's return address to achieve arbitrary code execution or a device crash. The vendor has confirmed this product is end-of-life (EOL) and no patch will be released.

Affected products

  • TRENDnet TEW-432BRP 3.10B20

Timeline

  • 2009: other: Product reached End-of-Life (EOL) status
  • 2026-05-31: advisory: Vulnerability disclosed and CVE assigned

References

Related threats