Executive brief
A vulnerability exists in the TRENDnet TEW-432BRP wireless router that could allow an attacker to crash the device or execute unauthorized commands. By sending a specially crafted web request to the router's configuration interface, an attacker can disrupt network services or gain full control over the hardware. This product has reached its end-of-life status and will not receive security updates, meaning the manufacturer will not provide a fix.
Technical details
A stack-based buffer overflow vulnerability exists in the 'formWlanSetup' function within the '/goform/formWlanSetup' endpoint of the TRENDnet TEW-432BRP router (firmware 3.10B20). The 'enrollee' POST parameter is copied into a local stack variable without adequate bounds checking. A remote attacker with low privileges (authenticated access to the web interface) can provide an oversized string to overwrite the return address, leading to arbitrary code execution or a device crash (DoS). A public exploit is available. The vendor has stated that no patch will be released as the product has been End-of-Life (EOL) since 2009.
Affected products
- TRENDnet TEW-432BRP 3.10B20
Timeline
- 2009: other: Product reached End-of-Life (EOL) status
- 2026-05-31: disclosed: Vulnerability details and PoC published by researcher
- 2026-05-31: advisory: CVE-2026-10183 published