Impact
An attacker can trigger a stack‑based buffer overflow by supplying a specially crafted value for the addQos/comment/entry_name argument in the /boafrm/formIpQoS handler. The overflow can be triggered remotely and may allow the attacker to compromise the router with the privileges of the web management interface. The flaw is identified as CWE‑119 and CWE‑121, representing uncontrolled buffer overflows.
Affected Systems
The flaw is present only in the Totolink A3002MU firmware version 1.0.0‑B20230403.1455. Devices running this firmware expose the vulnerability through the web‑based QoS Rule feature. The vulnerability is specific to the Totolink A3002MU product line.
Risk and Exploitability
The CVSS score of 10 indicates a critical severity. Remote exploitation is explicitly possible, and the exploit has been publicly disclosed. The EPSS score is 1%. The vulnerability is not listed in the CISA KEV catalog, but the publicly available exploit evidence indicates an urgency for exposed devices.
OpenCVE Enrichment