External risk intelligence

Totolink A3002MU QoS Rule Handler Stack Buffer Overflow

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-105285

The affected product is a consumer router (Totolink A3002MU), which is designed to be directly connected to the internet. The vulnerability exists in a web-based management interface component, making it an internet-exposed service by design in common deployment patterns.

Memory Corruption

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security vulnerability has been identified in a consumer networking device, specifically within its Quality of Service (QoS) rule handling. This issue allows for remote exploitation due to a buffer overflow, meaning an attacker could potentially gain unauthorized access or control by sending specially crafted data over the network without any prior privileges. The exploit has been publicly disclosed, increasing the potential for its use.

  • A bug lets attackers take over devices remotely.
  • Critical consumer routers are the target.
  • Confirm device relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker can remotely exploit this vulnerability by sending specially crafted data to the device. This data targets the QoS Rule Handler component, specifically manipulating arguments within the `/boafrm/formIpQoS` file. Successful exploitation could lead to a stack-based buffer overflow, potentially allowing the attacker to gain control over the device.

  • No authentication or special access needed.
  • Manipulate QoS Rule Handler arguments.
  • Remote code execution and network compromise.

Live Threat

Current exploitation, exposure, and threat context

A stack-based buffer overflow vulnerability in the QoS Rule Handler component of the Totolink A3002MU router could allow an unauthenticated remote attacker to execute arbitrary code. This could happen when an attacker manipulates specific arguments within the `/boafrm/formIpQoS` file. The exploit has been publicly disclosed, increasing the likelihood of its use.

  • Router's management interface could be compromised.
  • Malicious input sent to the router's web interface.
  • Potential for device control or denial of service.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability, affecting the Totolink A3002MU router, likely falls under the responsibility of network or infrastructure teams, with potential involvement from vendor management if a solution requires vendor intervention. The initial action should focus on identifying all instances of this router, assessing their internet reachability and business criticality, and then locating the accountable owner for remediation planning.

  • Own the issue based on asset inventory.
  • Verify internet exposure and business impact.
  • Plan vendor coordination and remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Totolink A3002MU router?

The Totolink A3002MU is a consumer-grade wireless router designed to provide home or small office network connectivity. It includes an integrated web-based management interface that allows users to configure features like Quality of Service (QoS) rules to prioritize internet traffic for specific applications or devices.

What does CVE-2026-105285 mean for security?

This vulnerability is a stack-based buffer overflow, categorized as CWE-121. It occurs when the router's software tries to store more data in a memory buffer than it can hold. By sending specifically crafted input to the QoS handler, an attacker can overwrite adjacent memory, potentially causing the device to crash or allowing them to execute unauthorized commands.

How is this vulnerability triggered?

An attacker triggers this bug by sending malformed data to the QoS Rule Handler component via the /boafrm/formIpQoS file. The vulnerability is triggered through the manipulation of arguments like 'addQos', 'comment', or 'entry_name'. It is important to note that no prior authentication or administrative access to the router is required to initiate this process.

Is my device relevant to this CVE?

According to Halo Surface Signal, this router is designed for direct internet connectivity, which frequently results in the management interface being exposed to the web. If your Totolink A3002MU is configured with its management interface reachable from the public internet, it is at higher risk of remote exploitation.

What steps should I take if I use this router?

First, verify if you are running the affected version, 1.0.0-B20230403.1455. If you are, prioritize restricting access to the web management interface so it is not reachable from the public internet. Check the official Totolink support resources for any available firmware updates and coordinate with your network administrator to assess the device's business impact.

References