PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-10119 TRENDnet CVE debrief

A stack-based buffer overflow in the TRENDnet TEW-432BRP 3.10B20 router's formSetMACFilter function allows remote attackers to execute arbitrary code via a crafted filter_name parameter. The vendor has explicitly declined to provide a fix, noting the product reached end-of-life in 2009 (15 years ago) and cannot be patched. Public exploit disclosure increases immediate risk for any remaining deployed units.

Vendor
TRENDnet
Product
TEW-432BRP
CVSS
HIGH 7.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-30
Original CVE updated
2026-05-30
Advisory published
2026-05-30
Advisory updated
2026-05-30

Who should care

Organizations with legacy network infrastructure, particularly small business and home office deployments where TRENDnet TEW-432BRP routers may remain in service. Security teams responsible for asset inventory and vulnerability management. Network administrators managing router firmware lifecycles.

Technical summary

The formSetMACFilter function in /goform/formSetMACFilter on TRENDnet TEW-432BRP 3.10B20 fails to properly validate the length of the filter_name parameter, resulting in a stack-based buffer overflow (CWE-121). Remote exploitation is possible without user interaction. The vendor confirmed the vulnerability but stated the product has been end-of-life since 2009 and cannot be fixed. A public exploit has been released.

Defensive priority

critical

Recommended defensive actions

  • Immediately remove all TRENDnet TEW-432BRP devices from production networks; no patch will be issued due to 15-year EOL status
  • Block or restrict access to /goform/formSetMACFilter at network perimeter if device retirement is not immediately feasible
  • Segment EOL devices into isolated network zones with no internet access and minimal internal connectivity
  • Monitor for suspicious traffic targeting router management interfaces, particularly HTTP requests to /goform/formSetMACFilter
  • Inventory network infrastructure to identify any additional TRENDnet TEW-432BRP or similarly EOL equipment requiring replacement
  • resourceLinkAnnotations: [ref-4] [ref-6] [cve-org] [nvd]

Evidence notes

Vulnerability confirmed through Vuldb CNA submission with public exploit disclosure. CVSS 4.0 vector indicates network attack vector with low attack complexity, no user interaction, and high impact to confidentiality, integrity, and availability. Vendor EOL statement explicitly acknowledges vulnerability but declines remediation due to 15-year product discontinuation.

Official resources

public