Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.4

CVE-2026-10183: TRENDnet TEW-432BRP Router: Unauthenticated Remote Code Execution

CVE-2026-10183
Summary

A security flaw exists in an older version of the TRENDnet TEW-432BRP router software. This issue can be exploited remotely, potentially allowing an attacker to take control of the device. Due to the age of the software, the vendor will not be releasing a fix.

Original title
A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. This affects the function formWlanSetup of the file /goform/formWlanSetup. The manipulation of the argument enrollee leads to stack-ba...
Original description
A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. This affects the function formWlanSetup of the file /goform/formWlanSetup. The manipulation of the argument enrollee leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
nvd CVSS2.0 9.0
nvd CVSS3.1 8.8
nvd CVSS4.0 7.4
Vulnerability type
CWE-119 Buffer Overflow
CWE-121 Stack-based Buffer Overflow
Published: 31 May 2026 · Updated: 31 May 2026 · First seen: 31 May 2026