CVE-2026-10181: TRENDnet TEW-432BRP formSysCmd stack-based overflow
A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSysCmd of the file /goform/formSysCmd. Performing a manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10181?
The severity of CVE-2026-10181 is high with a score of 8.8.
How do I fix CVE-2026-10181?
To fix CVE-2026-10181, update the TRENDnet TEW-432BRP firmware to the latest version released by the vendor.
What type of vulnerability is CVE-2026-10181?
CVE-2026-10181 is a stack-based buffer overflow vulnerability.
Can CVE-2026-10181 be exploited remotely?
Yes, CVE-2026-10181 can be exploited remotely by manipulating the submit-url argument.
What systems are affected by CVE-2026-10181?
CVE-2026-10181 affects the TRENDnet TEW-432BRP router running firmware version 3.10B20.