Sceawere

Vulnerability Detail

CVE-2026-105285UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Totolink A3002MU Stack Buffer Overflow

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
9h ago
Vendor
Totolink
Product
A3002MU
Attack Type
Stack-based Buffer Overflow
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file /boafrm/formIpQoS of the component QoS Rule Handler. The manipulation of the argument addQos/comment/entry_name leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-10-05T10:16:38.520Z",
  "pubdate": "2026-10-05T10:16:38.520Z",
  "executiveSummary": "A stack-based buffer overflow vulnerability has been identified in the Totolink A3002MU router, specifically within the QoS Rule Handler component. The flaw resides in the /boafrm/formIpQoS script, triggered via improper input validation of the addQos, comment, and entry_name parameters.\nThis vulnerability allows a remote, unauthenticated attacker to inject maliciously crafted data into the system, leading to a stack-based buffer overflow. Successful exploitation can result in arbitrary code execution, denial of service (device crash), or potential system compromise.\nGiven that the exploit code has been publicly disclosed, the risk is classified as critical, necessitating immediate remediation efforts to prevent unauthorized remote exploitation by malicious actors.",
  "technicalDetails": "The vulnerability exists within the QoS (Quality of Service) management functionality of the Totolink A3002MU firmware version 1.0.0-B20230403.1455. The target component is the /boafrm/formIpQoS handler, which processes configuration requests submitted via HTTP POST or GET methods.\nThe root cause is a failure to enforce sufficient bounds checking on user-supplied input arguments: addQos, comment, and entry_name. When the web server receives an HTTP request containing these parameters, the internal QoS Rule Handler function copies the provided strings into fixed-length stack buffers without verifying their size. By providing an input length that exceeds the pre-allocated buffer capacity, an attacker can overwrite adjacent stack memory, including critical data such as the saved return address or function pointers.\nThe exploitation flow begins with the attacker constructing a specially crafted HTTP request containing an oversized payload within the vulnerable parameters. Because the application fails to perform input sanitization or length verification, the buffer overflow occurs during the copying process. By carefully crafting the payload, an attacker can achieve control over the instruction pointer (EIP/RIP) upon function return.\nSince the /boafrm/formIpQoS endpoint is accessible remotely without explicit session validation in certain contexts, an unauthenticated attacker can trigger the overflow from the network. The payload can be engineered to inject malicious shellcode, redirect execution to a ROP (Return Oriented Programming) chain, or cause the device to hang, leading to a complete denial of service. The impact of successful exploitation is significant, as it grants the attacker the ability to execute commands with the privileges of the web service process, which frequently possesses elevated (root) access on embedded SOHO routing devices. The public availability of the exploit increases the likelihood of opportunistic attacks targeting this specific firmware version."
}
CVE-2026-105285: Totolink A3002MU Stack Buffer Overflow (CRITICAL Severity, CVSS: 10.0) | Sceawere