Executive brief
A security vulnerability exists in the Totolink A3002MU wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted web request. This could lead to a complete loss of internet service, unauthorized access to the network, or the theft of sensitive data passing through the router.
Technical details
A stack-based buffer overflow vulnerability exists in the Totolink A3002MU router, specifically within the 'sub_410188' function of the '/boafrm/formWlanSetup' component. The flaw is triggered by improper handling of the 'wan-url' argument in HTTP requests processed by the device's HTTP Request Handler. A remote attacker with low privileges can exploit this by sending a crafted request to the vulnerable endpoint, leading to memory corruption. Successful exploitation can result in arbitrary code execution or a persistent denial-of-service (DoS) condition. Public exploit code has been released for this vulnerability.
Affected products
- Totolink A3002MU B20211125.1046
Timeline
- 2026-04-13: advisory: Initial disclosure by VulDB and NVD