PT-2026-45162 · Trendnet · Tew-432Brp

Pjq_Buoy

·

Published

2026-05-31

·

Updated

2026-05-31

·

CVE-2026-10158

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. Affected is the function formPortFw of the file /goform/formPortFw. The manipulation of the argument server name results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.

Exploit

Fix

Buffer Overflow

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-10158

Affected Products

Tew-432Brp