Impact
The flaw exists in the formSchedule function of the /boafrm/formSchedule endpoint on Totolink A3002MU routers. An attacker can send a specially crafted request to the webpage argument, causing a buffer overflow. This vulnerability can be triggered over the network, giving an attacker potential execution of arbitrary code on the device, compromising confidentiality, integrity, and availability. The vulnerability is a classic stack-based buffer overflow (CWE-119) and also involves an unchecked buffer copy (CWE-120).
Affected Systems
Totolink manufactures the A3002MU series Wi‑Fi router. Vulnerability affects firmware version Hh-B20211125.1046. Any deployed A3002MU devices with this firmware configuration are at risk.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity, the EPSS score of less than 1% shows low probability of exploitation at present, and the vulnerability is not listed in CISA KEV. Nevertheless, the publicly available exploit means attackers can remotely trigger buffer overflow. Exploitation requires reaching the formSchedule endpoint and sending an over‑length webpage value; no local privilege escalation is needed, making it exploitable by remote attackers with network access.
OpenCVE Enrichment