Executive brief
The Totolink A3002MU wireless router contains a buffer overflow vulnerability in its web-based management interface. An attacker can send a specially crafted HTTP request with an oversized parameter to the router's configuration form, causing the web server process to crash and making the router's management interface inaccessible. This results in a denial-of-service condition that prevents administrators from accessing the router remotely.
Technical details
A buffer overflow exists in the /bin/boa web server's formWlAc function when processing the submit-url POST parameter. The vulnerable code performs unsafe string copying without proper length validation, allowing an attacker to overwrite adjacent memory by sending an HTTP POST request with an excessively long submit-url value. This results in a crash of the Boa process, causing denial of service.
Affected products
- Totolink A3002MU Hh-B20211125.1046
Timeline
- 2026-09-18: disclosed