Executive brief
The Totolink A3002MU wireless router contains a buffer overflow vulnerability in its web-based management interface. An attacker on the network can send a specially crafted request with an oversized parameter to crash the router's web server, causing it to stop responding and denying access to network management. This could potentially allow arbitrary code execution, giving an attacker complete control over the router.
Technical details
A buffer overflow exists in the formWlEncrypt function of the /bin/boa web server, triggered by the submit-url parameter which is copied into a fixed-size buffer without proper length validation. An unauthenticated remote attacker can exploit this via a POST request to /boafrm/formWlEncrypt with an oversized submit-url value, causing a denial-of-service condition and potentially achieving remote code execution.
Affected products
- Totolink A3002MU Hh-B20211125.1046
Timeline
- 2026-09-18: disclosed