PT-2026-90995 · Totolink · A3002Mu
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Totolink A3002MU version Hh-B20211125.1046
Description
A remote buffer overflow exists within the boa component. The issue occurs in the
formNewSchedule() function located in the /boafrm/formNewSchedule file. An attacker can trigger this by manipulating the submit-url argument.Recommendations
For version Hh-B20211125.1046, check for and apply the latest vendor firmware.
Remove remote administration exposure.
Restrict management interfaces to trusted networks.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
A3002Mu