Executive brief
The Totolink A3002MU router contains a buffer overflow vulnerability in its web management interface. An attacker can send a specially crafted request to crash the router's web server, causing the management interface to become unavailable. Since the router is typically accessible over the network, an unauthenticated attacker can exploit this vulnerability remotely to disrupt device management and operations.
Technical details
A buffer overflow vulnerability exists in the boa web server's formNewSchedule function, triggered by improper validation of the submit-url parameter in HTTP POST requests to /boafrm/formNewSchedule. The vulnerable code uses unsafe string-copy logic to copy user-supplied input into a fixed-size buffer without enforcing length boundaries, allowing an oversized parameter value to overwrite adjacent memory. The attack requires network reachability to the router's web interface but does not require authentication. Successful exploitation crashes the boa process, achieving denial of service of the web management interface. The vulnerability is publicly disclosed with proof-of-concept code available.
Affected products
- Totolink A3002MU Hh-B20211125.1046
Timeline
- 2026-09-14: disclosed: Vulnerability published on NVD
- 2026-09-14: exploited: Exploit code made public via GitHub