Impact
A buffer overflow exists in the formWlAc function of Totolink A3002MU firmware Hh-B20211125.1046 when processing the submit-url argument, allowing an attacker to overwrite memory and execute arbitrary code. The vulnerability is classified as CWE-119 and CWE-120 and can be triggered from a remote network location.
Affected Systems
The affected device is the Totolink A3002MU model running firmware version Hh-B20211125.1046. No other models or firmware revisions are currently documented as vulnerable.
Risk and Exploitability
The CVSS score of 9.4 indicates a severe risk level. The EPSS score is not available, but the vulnerability has been publicly disclosed and could be actively exploited. The device can be attacked remotely through the formWlAc interface, and the exploit can be executed by sending a crafted submit-url value. The vulnerability is not listed in the CISA KEV catalog at this time, but the high severity and remote nature warrant immediate attention.
OpenCVE Enrichment