Impact
This vulnerability occurs in the anchor tag handler of the Totolink A3002MU device. Malicious input can be crafted to inject arbitrary JavaScript into the web interface, enabling an attacker to run code in the context of the victim’s browser. The flaw is a classic cross‑site scripting weakness (CWE‑79) combined with a code‑execution capability in the handler (CWE‑94). Remote attackers can trigger the flaw by sending specially formatted requests to the device’s management interface, and the publicly released exploit demonstrates that the attack can be performed over the network without additional credentials.
Affected Systems
Affected is the Totolink A3002MU router running firmware image Hh-B20211125.1046. The vulnerable component is the Anchor Tag Handler; no other product variants are listed as impacted.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, while the EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring only network access to the device’s web interface. Because the flaw allows arbitrary script injection, an attacker could steal credentials, hijack sessions, or redirect users to malicious sites, thereby compromising confidentiality and integrity of the device’s configuration.
OpenCVE Enrichment