TRENDnet TEW-432BRP Stack-Based Buffer Overflow Vulnerability

Vulnerability

A stack-based buffer overflow vulnerability has been identified in the TRENDnet TEW-432BRP router, specifically in version 3.10B20. The issue arises in the 'formSetRoute' function within the '/goform/formSetRoute' file, where the 'ip', 'mask', and 'gateway' parameters are not properly validated. This lack of input sanitization allows for excessive data to be sent, overwriting the return address and potentially leading to arbitrary code execution. The vulnerability can be exploited remotely.

Impact

Exploitation of this vulnerability causes the router to crash, disrupting its normal service and functionality.

Reproduction

The vulnerability can be reproduced by sending a POST request to '/goform/formSetRoute' with overly long 'ip' parameter data. This can be done using a web browser or a tool like curl, ensuring that the 'Content-Type' is set to 'application/x-www-form-urlencoded'. The request must include authorization credentials for an admin user.

Added: May 29, 2026, 3:23 PM
Updated: May 29, 2026, 3:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.2
remediation
0.0
relevance
9.3
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.