Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.4

CVE-2026-10120: TRENDnet Router Firewall Rule Manipulation Allows Remote Attack

CVE-2026-10120
Summary

A security flaw in an old version of the TRENDnet TEW-432BRP router's firewall settings can be exploited remotely. This issue only affects routers that are no longer supported by the manufacturer. Since the router is outdated, it's unlikely to be fixed, but users should still be aware of the risk and consider replacing the device.

Original title
A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSetFirewallRule of the file /goform/formSetFirewallRule. The manipulation of the argument firew...
Original description
A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSetFirewallRule of the file /goform/formSetFirewallRule. The manipulation of the argument firewall_name results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
nvd CVSS2.0 9.0
nvd CVSS3.1 8.8
nvd CVSS4.0 7.4
Vulnerability type
CWE-119 Buffer Overflow
CWE-121 Stack-based Buffer Overflow
Published: 30 May 2026 · Updated: 1 Jun 2026 · First seen: 30 May 2026