CVE-2026-4172
HIGHTRENDnet TEW-632BRP HTTP POST Request ping_response.cgi stack-based overflow
Title source: cnaDescription
A vulnerability was detected in TRENDnet TEW-632BRP 1.010B32. This affects an unknown part of the file /ping_response.cgi of the component HTTP POST Request Handler. The manipulation of the argument ping_ipaddr results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Scores
CVSS v3
7.2
EPSS
0.0005
EPSS Percentile
16.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-119
CWE-121
Status
published
Products (1)
TRENDnet/TEW-632BRP
1.010B32
Published
Mar 16, 2026
Tracked Since
Mar 16, 2026