Severity
8.8HIGH
EPSS
0.2%
top 64.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 17

Description

TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the vpnUser or vpnPassword` parameters in the formFilter function.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

NVDtotolink/a3002ru_firmware2.1.1-b20211108.1455

🔴Vulnerability Details

2
CVEList
CVE-2026-26732: TOTOLINK A3002RU V22026-02-17
GHSA
GHSA-pqh8-xq2x-mwg2: TOTOLINK A3002RU V22026-02-17
CVE-2026-26732 (HIGH CVSS 8.8) | TOTOLINK A3002RU V2.1.1-B20211108.1 | cvebase.io