Executive brief
A security vulnerability exists in the TRENDnet TEW-432BRP wireless router, a device used to provide internet connectivity for home and small office networks. An attacker can exploit this flaw to take control of the device, potentially leading to a complete service outage or unauthorized access to network traffic. Because this product reached its end-of-life in 2009, the manufacturer will not be releasing a security patch, and users are advised to replace the hardware.
Technical details
A stack-based buffer overflow vulnerability (CWE-121) exists in the TRENDnet TEW-432BRP firmware version 3.10B20. The flaw is located within the 'formSysCmd' function in the '/goform/formSysCmd' file, where improper validation of the 'submit-url' argument allows for memory corruption. A remote attacker with low privileges can exploit this by sending a specially crafted request to the web interface. Successful exploitation can lead to arbitrary code execution or a denial-of-service condition. The vendor has stated that no patch will be issued as the product has been end-of-life (EOL) since 2009.
Affected products
- TRENDnet TEW-432BRP 3.10B20
Timeline
- 2026-05-31: disclosed: Vulnerability published via VulDB and NVD