CVE-2026-10161: TRENDnet TEW-432BRP formResetStatistic stack-based overflow
A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. This affects the function formResetStatistic of the file /goform/formResetStatistic. Performing a manipulation of the argument statusstatistic results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10161?
CVE-2026-10161 has a high severity rating of 8.8.
How do I fix CVE-2026-10161?
To fix CVE-2026-10161, update the TRENDnet TEW-432BRP to the latest firmware version provided by the manufacturer.
What impact does CVE-2026-10161 have on my device?
CVE-2026-10161 can lead to a stack-based buffer overflow, potentially allowing remote attackers to gain unauthorized access or control of the device.
Is CVE-2026-10161 exploitable remotely?
Yes, CVE-2026-10161 is exploitable remotely, which increases the risk of unauthorized access.
Which product is affected by CVE-2026-10161?
CVE-2026-10161 affects the TRENDnet TEW-432BRP model running firmware version 3.10B20.