Impact
A buffer overflow in the formWlWds function of the Totolink A3002MU router’s web management interface can be triggered by manipulating the submit-url argument, allowing an attacker to execute arbitrary code remotely. The flaw is classified under CWE-119 (Buffer Access with Incorrect Length Value) and CWE-120 (Improper Validation of Array Index). The existence of a publicly released exploit indicates that exploiting this vulnerability is straightforward once the device is reachable over the internet.
Affected Systems
The vulnerability affects the Totolink A3002MU model running firmware Hh-B20211125.1046. No other specific versions or vendor variants are listed; only this model is mentioned in the advisory.
Risk and Exploitability
The CVSS score is 10, indicating critical severity. Although the EPSS score is not available, the public availability of an exploit and the capability to launch the attack remotely raise the likelihood of real-world exploitation. The vulnerability is not listed in the CISA KEV catalog, but the high CVSS and known exploit still demand immediate remediation. The likely attack vector is remote access through the router’s web interface, which can reach the vulnerable endpoint from external networks.
OpenCVE Enrichment