Impact
A buffer overflow exists in the formIpv6Setup function of the A3002MU router’s boa component. By sending a crafted static_ipv6 argument, an attacker can overflow the buffer, possibly executing arbitrary code. The flaw is actively exploitable remotely, with publicly disclosed exploits available.
Affected Systems
The vulnerability affects the Totolink A3002MU model, firmware version Hh‑B20211125.1046. No other models or firmware versions are listed as affected.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. The EPSS score is < 1% (approximately 0.005), reflecting a very low but nonzero exploitation probability. The existence of public exploits and remote attack feasibility suggests a high likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. An attacker can trigger the overflow by targeting the formIpv6Setup endpoint from outside the device, using a crafted static_ipv6 payload, leading potentially to remote code execution.
OpenCVE Enrichment