CVE-2026-105285: Totolink A3002MU QoS Rule formIpQoS stack-based overflow
A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file /boafrm/formIpQoS of the component QoS Rule Handler. The manipulation of the argument addQos/comment/entryname leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue is remotely exploitable and the supplied vector indicates no privileges or user interaction are required. Exploitation targets the QoS Rule Handler through the /boafrm/formIpQoS endpoint.
Which inputs are implicated in the overflow?
The affected request arguments are addQos, comment, and entry_name. Manipulation of these arguments can trigger a stack-based buffer overflow.
How likely is exploitation in practice?
A public exploit has been disclosed and may be used. The available assessment rates the issue as critical, with high impacts to confidentiality, integrity, and availability.