CVE-2026-36837

7.5

TOTOLINK · A3002RU V3

A stack-based buffer overflow in the TOTOLINK A3002RU V3 allows unauthenticated attackers to cause a denial of service via the hostname parameter in the formMapDelDevice function.

Executive summary

A critical stack-based buffer overflow vulnerability in TOTOLINK A3002RU V3 routers allows unauthenticated remote attackers to crash the device, posing a significant availability risk.

Vulnerability

The device is susceptible to a stack-based buffer overflow triggered by sending a crafted request to the hostname parameter within the formMapDelDevice function. This flaw is exploitable by an unauthenticated attacker over the network.

Business impact

The exploitation of this vulnerability results in a denial of service, which can lead to critical network downtime for users relying on the affected hardware. Given the CVSS score of 7.5, this high-severity flaw poses a substantial risk to operational continuity, especially for organizations that use these devices as primary network gateways.

Remediation

Immediate Action: Monitor official TOTOLINK support channels for the release of a firmware update that addresses the buffer overflow in the formMapDelDevice function and apply it immediately upon availability.

Proactive Monitoring: Inspect network traffic for abnormal patterns directed at the device administration interface and review system logs for recurring service crashes or unexpected reboots.

Compensating Controls: Restrict access to the router management interface to trusted internal IP addresses only, and implement a firewall policy to block unsolicited traffic from the internet to the device management ports.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists as documented in the researcher write-up linked in the CVE references.

Analyst recommendation

Organizations utilizing the TOTOLINK A3002RU V3 should verify the current firmware version and prepare for immediate deployment of patches. Given the availability of a public proof-of-concept, the attack surface should be minimized by isolating the management interface from public-facing networks until a formal vendor fix is applied.

More TOTOLINK CVEs

Sources