Impact
A buffer overflow exists in the formWlEncrypt function of the Totolink A3002MU firmware Hh-B20211125.1046. Manipulating the submit‑url argument overflows an internal buffer, allowing an attacker to execute arbitrary code. The flaw is located in the /boafrm/formWlEncrypt file and is a classic index-based overflow, classified under CWE‑119 and CWE‑120. Because the overflow can be triggered from a remote web request, the result is a complete compromise of the device if an exploit is successfully delivered.
Affected Systems
Devices running the Totolink A3002MU router, firmware version Hh‑B20211125.1046, expose the vulnerable formWlEncrypt code. No additional third‑party or older firmware versions are listed as affected in the current data.
Risk and Exploitability
The vulnerability scores a CVSS of 10, indicating critical severity. The EPSS score is not available, but public exploit code is known and the vulnerability is noted as exploitable remotely. Although it is not listed in the CISA KEV catalog yet, the combination of a remote trigger and a zero‑day exploit scenario warrants a high risk assessment.
OpenCVE Enrichment