Impact
Totolink A3002MU routers expose a flaw in the File Upload Handler that allows an attacker to manipulate the filename parameter and perform a path traversal attack. The vulnerability is triggered by the sub_44B250 function within the /boafrm/formUploadFile component and can be exploited remotely through the web interface. By sending a crafted filename containing traversal characters, an attacker can cause files to be written or read from arbitrary locations on the device’s filesystem, which may lead to unauthorized configuration changes or further exploitation.
Affected Systems
The issue affects all A3002MU devices running firmware version 1.0.0-B20230403.1455. No other firmware versions have been identified as vulnerable at this time.
Risk and Exploitability
The CVSS score of 5.3 places this vulnerability in the medium severity range. However, the public availability of an exploit and the remote nature of the attack elevate the real‑world risk. The EPSS score is not provided, and the flaw is not listed in the CISA KEV catalog. Because the threat involves remote manipulation of file uploads, an attacker can potentially write arbitrary files to the router’s file system and then execute them, resulting in complete loss of confidentiality, integrity, and availability. The lack of an immediate patch maintains a high risk until a vendor update or workaround is enforced.
OpenCVE Enrichment