Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.4

CVE-2026-10181: TRENDnet TEW-432BRP: Remote Attack via Misused Router Function

CVE-2026-10181
Summary

A vulnerability in a 15-year-old router model allows hackers to remotely exploit a security weakness. This issue affects old, unsupported products, and users are advised to replace them with newer, secure models to prevent potential attacks.

Original title
A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSysCmd of the file /goform/formSysCmd. Performing a manipulation of the argument submit-url result...
Original description
A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSysCmd of the file /goform/formSysCmd. Performing a manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
nvd CVSS2.0 9.0
nvd CVSS3.1 8.8
nvd CVSS4.0 7.4
Vulnerability type
CWE-119 Buffer Overflow
CWE-121 Stack-based Buffer Overflow
Published: 31 May 2026 · Updated: 31 May 2026 · First seen: 31 May 2026