Impact
A buffer overflow exists in the formFilter function of the boa component on the Totolink A3002MU router. Manipulating the ip6addr argument can overflow an internal buffer, which could allow an attacker to hijack program execution if the attacker controls the overflow. This potential for arbitrary code execution is inferred, as the CVE description does not explicitly confirm it. The vulnerability is classified as a stack-based buffer overflow (CWE-120) and a general buffer overrun (CWE-119), and it can lead to remote code execution, compromising confidentiality, integrity, and availability.
Affected Systems
The Totolink A3002MU router running firmware version Hh-B20211125.1046 is affected, specifically the formFilter function in the Boa component located at /boafrm/formFilter. No other vendors, products, or firmware revisions are reported to be impacted.
Risk and Exploitability
The CVSS score is 9.4, indicating critical severity. The EPSS score is less than 1%, indicating a very low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote; an attacker can trigger the flaw by sending a crafted ip6addr value to the vulnerable endpoint. Because the overflow corrupts the stack, a public exploit could lead to arbitrary code execution (inferred).
OpenCVE Enrichment