CVE-2026-10162: TRENDnet TEW-432BRP formSetPassword stack-based overflow
A flaw has been found in TRENDnet TEW-432BRP 3.10B20. This vulnerability affects the function formSetPassword of the file /goform/formSetPassword. Executing a manipulation of the argument webpage can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10162?
CVE-2026-10162 is classified as high severity with a CVSS score of 8.8.
How do I fix CVE-2026-10162?
Updating the firmware of the TRENDnet TEW-432BRP to the latest version can mitigate the vulnerability CVE-2026-10162.
What type of vulnerability is CVE-2026-10162?
CVE-2026-10162 is a stack-based buffer overflow vulnerability.
Can CVE-2026-10162 be exploited remotely?
Yes, CVE-2026-10162 allows for remote exploitation due to its vulnerability in the formSetPassword function.
Which device is affected by CVE-2026-10162?
The vulnerability CVE-2026-10162 affects the TRENDnet TEW-432BRP model.