CVE-2026-10123: TRENDnet TEW-432BRP formSetDomainFilter stack-based overflow
A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetDomainFilter of the file /goform/formSetDomainFilter. Performing a manipulation of the argument blockeddomain/permitteddomain/blockeddomainlist/permitteddomainlist results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10123?
The severity of CVE-2026-10123 is high with a score of 8.8.
What software is affected by CVE-2026-10123?
CVE-2026-10123 affects the TRENDnet TEW-432BRP router running version 3.10B20.
How does CVE-2026-10123 exploit the system?
CVE-2026-10123 exploits the system through a stack-based buffer overflow in the formSetDomainFilter function.
How can I fix CVE-2026-10123?
To fix CVE-2026-10123, update the TRENDnet TEW-432BRP to the latest firmware version, if available.
What impact does CVE-2026-10123 have on devices?
CVE-2026-10123 could allow attackers to execute arbitrary code, leading to potential data compromise or device control.