TOTOLINK A3002R Command Injection Vulnerability Allowing Remote Code Execution

Vulnerability

A command injection vulnerability has been identified in the TOTOLINK A3002R router, specifically in version V4.0.0-B20230531.1404. The issue arises in the web server component 'boa', where the 'bandstr' parameter is not properly sanitized. This flaw allows remote, unauthenticated attackers to execute arbitrary commands with root privileges.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the device, with the executed commands running as the root user.

Reproduction

The vulnerability can be reproduced by sending a POST request to '/boafrm/formMapDelDevice' with an unsanitized 'bandstr' parameter. This parameter can include malicious commands, which will be executed on the router's operating system.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
9.1
remediation
0.0
relevance
0.0
threat
7.1
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.