Junglewise Threat Intelligence

CVE-2026-10179: TRENDnet TEW-432BRP stack overflow in formSetWlanEncrypt

CVE-2026-10179 · Severity: high · CVSS 8.8 · Published 2026-05-31

Technologies: TRENDnet TEW-432BRP. Vendors: TRENDnet.

Executive brief

A security vulnerability exists in the TRENDnet TEW-432BRP wireless router that could allow a remote attacker to crash the device or execute unauthorized commands. This occurs when the router processes specific wireless encryption settings. Because this product reached its end-of-life in 2009, the manufacturer will not be releasing a fix, and users are advised to replace the hardware.

Technical details

A stack-based buffer overflow exists in the 'formSetWlanEncrypt' function within the '/goform/formSetWlanEncrypt' endpoint of the TRENDnet TEW-432BRP firmware (version 3.10B20). The vulnerability is caused by a lack of bounds checking on the 'webpage' argument, which is copied directly into a local stack variable. An authenticated remote attacker can exploit this by sending a specially crafted POST request with an oversized string, leading to a crash (DoS) or potential remote code execution by overwriting the function's return address. The vendor has confirmed this product is End-of-Life (EOL) and no patch will be provided.

Affected products

  • TRENDnet TEW-432BRP 3.10B20

Timeline

  • 2026-05-31: disclosed
  • 2026-05-31: advisory

References

Related threats