PatchSiren cyber security CVE debrief
CVE-2026-10119 TRENDnet CVE debrief
A stack-based buffer overflow in the TRENDnet TEW-432BRP 3.10B20 router's formSetMACFilter function allows remote attackers to execute arbitrary code via a crafted filter_name parameter. The vendor has explicitly declined to provide a fix, noting the product reached end-of-life in 2009 (15 years ago) and cannot be patched. Public exploit disclosure increases immediate risk for any remaining deployed units.
- Vendor
- TRENDnet
- Product
- TEW-432BRP
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-30
- Original CVE updated
- 2026-05-30
- Advisory published
- 2026-05-30
- Advisory updated
- 2026-05-30
Who should care
Organizations with legacy network infrastructure, particularly small business and home office deployments where TRENDnet TEW-432BRP routers may remain in service. Security teams responsible for asset inventory and vulnerability management. Network administrators managing router firmware lifecycles.
Technical summary
The formSetMACFilter function in /goform/formSetMACFilter on TRENDnet TEW-432BRP 3.10B20 fails to properly validate the length of the filter_name parameter, resulting in a stack-based buffer overflow (CWE-121). Remote exploitation is possible without user interaction. The vendor confirmed the vulnerability but stated the product has been end-of-life since 2009 and cannot be fixed. A public exploit has been released.
Defensive priority
critical
Recommended defensive actions
- Immediately remove all TRENDnet TEW-432BRP devices from production networks; no patch will be issued due to 15-year EOL status
- Block or restrict access to /goform/formSetMACFilter at network perimeter if device retirement is not immediately feasible
- Segment EOL devices into isolated network zones with no internet access and minimal internal connectivity
- Monitor for suspicious traffic targeting router management interfaces, particularly HTTP requests to /goform/formSetMACFilter
- Inventory network infrastructure to identify any additional TRENDnet TEW-432BRP or similarly EOL equipment requiring replacement
- resourceLinkAnnotations: [ref-4] [ref-6] [cve-org] [nvd]
Evidence notes
Vulnerability confirmed through Vuldb CNA submission with public exploit disclosure. CVSS 4.0 vector indicates network attack vector with low attack complexity, no user interaction, and high impact to confidentiality, integrity, and availability. Vendor EOL statement explicitly acknowledges vulnerability but declines remediation due to 15-year product discontinuation.
Official resources
public