Impact
A buffer overflow in the Boa formNewSchedule function of Totolink A3002MU router firmware Hh-B20211125.1046 allows an attacker that can manipulate the submit-url argument to overflow a buffer. The overflow can lead to arbitrary code execution on the device. The vulnerability is a classic uncontrolled buffer overflow as identified by CWE-119 and CWE-120.
Affected Systems
Manufactured by Totolink, the affected device is the A3002MU router running firmware version Hh-B20211125.1046. The flaw resides in the Boa web interface component exposed under /boafrm/formNewSchedule.
Risk and Exploitability
The CVSS score of 9.4 classifies this issue as critical, and the EPSS score is < 1%, indicating a very low but nonzero exploitation probability. The vulnerability is publicly documented and an exploit is known to be available. The attack can be performed from a remote host, implying that any external attacker who can reach the router’s web interface may target the flaw. The lack of a KEV listing does not reduce the urgency, as the exploit is openly shared and could be used in targeted or mass‑scale attacks.
OpenCVE Enrichment