Impact
A buffer overflow flaw exists in the formPortFw function of the Totolink A3002MU device firmware. The vulnerability is triggered by manipulating the service_type argument, allowing an attacker to overwrite memory and potentially execute arbitrary code‑bounds write, leading to control‑flow hijack and full compromise of the device. This vulnerability is a classic stack‑based buffer overflow (CWE‑119) and an instance of unsafe buffer handling (CWE‑120).
Affected Systems
The affected product is the Totolink A3002MU wireless router, firmware build Hh-B20211125.1046. No other vendors or versions are indicated.
Risk and Exploitability
The flaw has a CVSS score of 9.4, signalling critical severity. Security researchers have already published an exploit, and the vulnerability can be triggered remotely, likely through the router’s web interface, as inferred from the exploitation scenario. EPSS score is < 1%, but the publicly available exploit demonstrates that the attack is trivial to execute for a motivated actor. The issue is not listed in the CISA KEV catalog, yet its severity and remote nature warrant urgent action.
OpenCVE Enrichment