Junglewise Threat Intelligence

CVE-2026-10162: TRENDnet TEW-432BRP stack overflow in formSetPassword

CVE-2026-10162 · Severity: high · CVSS 8.8 · Published 2026-05-31

Technologies: TRENDnet TEW-432BRP. Vendors: TRENDnet.

Executive brief

A security vulnerability exists in the TRENDnet TEW-432BRP wireless router, a device used to provide internet connectivity for home and small office environments. An attacker can exploit this flaw to crash the router or potentially take full control of the device by sending a specially crafted request to the password management interface. Because this product reached its end-of-life in 2009, the manufacturer will not be providing a security patch, leaving affected devices permanently vulnerable.

Technical details

A stack-based buffer overflow exists in the 'formSetPassword' function within the '/goform/formSetPassword' endpoint of the TRENDnet TEW-432BRP router (firmware 3.10B20). The vulnerability is caused by a lack of bounds checking on the 'webpage' parameter, which is copied directly into a local stack variable. A remote attacker with low privileges (authenticated access) can exploit this by sending a long string in a POST request, overwriting the function's return address to achieve arbitrary code execution or a device crash. A public exploit (PoC) is available. The vendor has stated no fix will be released as the product has been end-of-life (EOL) since 2009.

Affected products

  • TRENDnet TEW-432BRP 3.10B20

Timeline

  • 2026-05-31: disclosed: Vulnerability details and PoC published by researcher.
  • 2026-05-31: advisory: CVE-2026-10162 published.

References

Related threats