在 Totolink A3002MU 1.0.0-B20230403.1455 版本中检测到一处安全漏洞。该漏洞影响 QoS 规则处理程序组件中的 /boafrm/formIpQoS 文件的某个未知函数。对参数 addQos/comment/entry_name 的操纵可导致基于栈的缓冲区溢出。此漏洞支持远程利用。该漏洞的利用代码已公开,可被恶意利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105284 | 10.0 CRITICAL | Totolink A3002MU Authentication Check boa sub_40FCFC improper authorization |
| CVE-2026-105286 | 6.3 MEDIUM | Totolink A3002MU File Upload formUploadFile sub_44B250 path traversal |
No comments yet