Executive brief
A security vulnerability exists in the TRENDnet TEW-432BRP wireless router that could allow a remote attacker to crash the device or execute unauthorized commands. This occurs when the router processes specific wireless encryption settings. Because this product reached its end-of-life in 2009, the manufacturer will not be releasing a fix, and users are advised to replace the hardware.
Technical details
A stack-based buffer overflow exists in the 'formSetWlanEncrypt' function within the '/goform/formSetWlanEncrypt' endpoint of the TRENDnet TEW-432BRP firmware (version 3.10B20). The vulnerability is caused by a lack of bounds checking on the 'webpage' argument, which is copied directly into a local stack variable. An authenticated remote attacker can exploit this by sending a specially crafted POST request with an oversized string, leading to a crash (DoS) or potential remote code execution by overwriting the function's return address. The vendor has confirmed this product is End-of-Life (EOL) and no patch will be provided.
Affected products
- TRENDnet TEW-432BRP 3.10B20
Timeline
- 2026-05-31: disclosed
- 2026-05-31: advisory