CVE-2022-29643 is a stack overflow vulnerability affecting TOTOLINK A3100R routers (firmware versions V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129). An unauthenticated attacker can trigger a Denial of Service (DoS) by sending a crafted POST request to the setMacQos function, manipulating the macAddress parameter. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity and no user interaction required. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in CISA's KEV catalog, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.1.2cu.5050_b20200504CPE matchmatch criteria | cpe:2.3:o:totolink:a3100r_firmware:4.1.2cu.5050_b20200504:*:*:*:*:*:*:* | ||
4.1.2cu.5247_b20211129CPE matchmatch criteria | cpe:2.3:o:totolink:a3100r_firmware:4.1.2cu.5247_b20211129:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.