Skip to main content
Vulnerability Database/CVE-2026-105285

CVE-2026-105285: Totolink A3002MU Buffer Overflow Vulnerability

CVE-2026-105285 is a stack-based buffer overflow flaw in Totolink A3002MU router that enables remote attackers to exploit the QoS Rule Handler. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-105285 Overview

CVE-2026-105285 is a stack-based buffer overflow in the Totolink A3002MU router running firmware version 1.0.0-B20230403.1455. The flaw resides in the QoS Rule Handler, specifically in the /boafrm/formIpQoS endpoint. Attackers can exploit the vulnerability remotely by manipulating the addQos, comment, or entry_name arguments. The weakness is categorized under [CWE-119] (Improper Restriction of Operations within the Bounds of a Memory Buffer). A public proof-of-concept has been disclosed, raising the risk of opportunistic exploitation against exposed devices.

Critical Impact

Remote, unauthenticated attackers can trigger a stack-based buffer overflow in the router's QoS handler, potentially leading to arbitrary code execution or device compromise.

Affected Products

  • Totolink A3002MU router
  • Firmware version 1.0.0-B20230403.1455
  • QoS Rule Handler component (/boafrm/formIpQoS)

Discovery Timeline

  • 2026-10-05 - CVE-2026-105285 published to NVD
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-105285

Vulnerability Analysis

The vulnerability affects the HTTP request handler bound to /boafrm/formIpQoS in the Totolink A3002MU web management interface. The handler processes QoS configuration input but fails to validate the length of user-supplied parameters before copying them into fixed-size stack buffers. Attackers who send a crafted POST request with oversized addQos, comment, or entry_name fields overwrite adjacent stack memory, including saved return addresses. The condition is reachable over the network without authentication, which widens the exposure to any attacker able to reach the device's web interface.

Root Cause

The root cause is improper bounds checking during string handling in the QoS rule parsing logic. The firmware uses unsafe copy operations such as strcpy or equivalent without enforcing a maximum length. This allows user input to extend beyond the destination buffer and corrupt the stack frame, consistent with [CWE-119].

Attack Vector

Exploitation requires network access to the router's HTTP management service. An attacker submits a crafted request to /boafrm/formIpQoS with an overlong value in one of the vulnerable parameters. Successful exploitation can crash the device (denial of service) or, with reliable ROP gadget selection on the device's MIPS or ARM firmware, lead to arbitrary code execution with the privileges of the web daemon. Public proof-of-concept material has been released, lowering the barrier to exploitation. See the GitHub PoC Repository and the VulDB CVE-2026-105285 entry for technical details.

Detection Methods for CVE-2026-105285

Indicators of Compromise

  • HTTP POST requests to /boafrm/formIpQoS containing abnormally long values in addQos, comment, or entry_name parameters.
  • Unexpected reboots, crashes, or httpd/boa process restarts on the Totolink A3002MU device.
  • Outbound connections from the router to unknown hosts following QoS configuration requests.

Detection Strategies

  • Inspect web server and reverse proxy logs for requests to /boafrm/formIpQoS with parameter lengths exceeding typical configuration values.
  • Deploy network intrusion detection signatures that flag oversized POST bodies targeting the QoS endpoint on Totolink management ports.
  • Correlate device reboots or management-plane errors with recent inbound HTTP traffic to the router.

Monitoring Recommendations

  • Continuously monitor administrative access to router management interfaces and alert on access from untrusted networks.
  • Track firmware version inventory to identify devices still running 1.0.0-B20230403.1455.
  • Baseline normal QoS configuration traffic and alert on deviations in request size or frequency.

How to Mitigate CVE-2026-105285

Immediate Actions Required

  • Restrict access to the router's web management interface to trusted internal networks only; block WAN-side management.
  • Change default credentials and enforce strong authentication on the device.
  • Audit exposed Totolink A3002MU devices and remove any publicly reachable management interfaces.

Patch Information

At the time of publication, no vendor patch has been referenced in the NVD entry. Consult the TOTOLINK Official Website for firmware updates and advisories. Where no fix is available, consider replacing the affected device or isolating it behind a firewall that blocks access to /boafrm/formIpQoS.

Workarounds

  • Disable remote (WAN) management on the router and restrict LAN-side access via ACLs.
  • Place the router behind a network firewall that filters HTTP requests to the vulnerable endpoint.
  • Segment IoT and network infrastructure devices away from user and server VLANs to limit lateral movement if the device is compromised.
bash
# Example firewall rule to block external access to the vulnerable endpoint
iptables -A INPUT -p tcp --dport 80 -m string --string "/boafrm/formIpQoS" --algo bm -j DROP
iptables -A INPUT -p tcp --dport 443 -m string --string "/boafrm/formIpQoS" --algo bm -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.