Impact
A flaw in the authentication check routine of the Totolink A3002MU firmware allows an attacker to manipulate input to the sub_40FCFC function within the /bin/boa component, resulting in improper authorization. The vulnerability permits an adversary to bypass normal authentication and gain unauthorized access to the device, potentially enabling further exploitation of the firmware. The description indicates that the flaw can be triggered remotely and has been made publicly available. Consequently, an attacker could obtain control or sensitive information without proper authentication. This weakness is classified under CWE-266 (Missing Authorization) and CWE-285 (Improper Authorization) and carries a CVSS score of 10.
Affected Systems
The affected product is the Totolink A3002MU router, current firmware version 1.0.0-B20230403.1455. No other versions or products are listed as impacted.
Risk and Exploitability
Because the flaw can be exploited from a remote source and a public exploit exists, the risk is high. The CVSS score of 10 emphasizes the critical severity. The EPSS score is not available, but the lack of KEV listing does not diminish the threat, as public knowledge and exploitation code are present. The attack vector is likely remote, potentially from the internet or an internal network that can reach the router's management interface. An attacker with the ability to reach the device could abuse this weakness to achieve unauthorized access and further lateral movement.
OpenCVE Enrichment