Impact
A command injection flaw exists in the formWsc function within the /boafrm/formWsc file of the Totolink A3002MU router. By manipulating the localPin argument, a remote attacker can inject arbitrary shell commands for execution. The vulnerability is a classic example of CWE-74 (Incorrect Parsing of Argument String) and CWE-77 (Improper Validation or Sanitization of Input). Successful exploitation would give the attacker complete control over the device, allowing data exfiltration, network pivoting, or further compromise of connected systems.
Affected Systems
The affected device is the Totolink A3002MU model, specifically firmware builds including Hh-B20211125.1046. No other vendor or product variants are listed as impacted.
Risk and Exploitability
The CVSS score of 9.4 classifies this flaw as Critical, and the EPSS score of 3% indicates a low‑to‑moderate likelihood of exploitation in the wild. The vulnerability is not registered in the CISA KEV catalog, yet public exploit code has already been posted, so a determined adversary can readily craft an attack. The attack vector is remote, requiring only network connectivity to the router’s web management interface, and no local privileges are needed.
OpenCVE Enrichment