CVE-2026-10063

A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument peerPin leads to stack-based buffer overflow. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
References
Link Resource
https://github.com/wudipjq/my_vuln/blob/main/TRENDnet/vuln_4/4.md Exploit Third Party Advisory
https://vuldb.com/submit/814759 Third Party Advisory VDB Entry
https://vuldb.com/vuln/367149 Third Party Advisory VDB Entry
https://vuldb.com/vuln/367149/cti Permissions Required VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:trendnet:tew-432brp_firmware:3.10b20:*:*:*:*:*:*:*
cpe:2.3:h:trendnet:tew-432brp:-:*:*:*:*:*:*:*

History

21 Jul 2026, 12:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad fue identificada en TRENDnet TEW-432BRP 3.10B20. Afectada por este problema es la función formWPS del archivo /goform/formWPS. Tal manipulación del argumento peerPin conduce a desbordamiento de búfer basado en pila. El ataque puede ser realizado desde remoto. El exploit está disponible públicamente y podría ser usado. El proveedor explica: 'Este producto ha estado EOL durante 15 años (desde 2009). Dado que el artículo ha estado EOL durante tanto tiempo, no podemos replicar ni solucionar ninguna vulnerabilidad.' Esta vulnerabilidad solo afecta a productos que ya no son compatibles por el mantenedor.

03 Jun 2026, 14:17

Type Values Removed Values Added
First Time Trendnet tew-432brp
Trendnet
Trendnet tew-432brp Firmware
References () https://github.com/wudipjq/my_vuln/blob/main/TRENDnet/vuln_4/4.md - () https://github.com/wudipjq/my_vuln/blob/main/TRENDnet/vuln_4/4.md - Exploit, Third Party Advisory
References () https://vuldb.com/submit/814759 - () https://vuldb.com/submit/814759 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/367149 - () https://vuldb.com/vuln/367149 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/367149/cti - () https://vuldb.com/vuln/367149/cti - Permissions Required, VDB Entry
CPE cpe:2.3:h:trendnet:tew-432brp:-:*:*:*:*:*:*:*
cpe:2.3:o:trendnet:tew-432brp_firmware:3.10b20:*:*:*:*:*:*:*

29 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 15:16

Updated : 2026-07-21 12:10


NVD link : CVE-2026-10063

Mitre link : CVE-2026-10063

CVE.ORG link : CVE-2026-10063


JSON object : View

Products Affected

trendnet

  • tew-432brp
  • tew-432brp_firmware
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-121

Stack-based Buffer Overflow