Disclosure summary
A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file /boafrm/formIpQoS of the component QoS Rule Handler. The manipulation of the argument addQos/comment/entry_name leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Source-reported weakness categories
CWE-119, CWE-121
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-105285
Open original source · Updated Oct 06, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
- NIST NVD record
- CVE Program record
- gist.github.com
- vuldb.com
- vuldb.com
- vuldb.com
- vuldb.com
- www.totolink.net
PUBLISHED 2026-10-05T06:16:38-04:00
MODIFIED 2026-10-06T11:04:52-04:00
INGESTED 2026-10-06T11:45:40-04:00