TOTOLINK A3002RU V3 <= V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the hostname parameter in the formMapDelDevice function.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-36837 is a stack-based buffer overflow vulnerability affecting TOTOLINK A3002RU V3 routers through version V3.0.0-B20220304.1804. The vulnerability exists in the formMapDelDevice function where unsanitized input to the hostname parameter allows attackers to overflow a stack buffer. This matters significantly because TOTOLINK routers are commonly deployed in enterprise and residential networks as edge devices controlling network access and traffic. Affected organizations using vulnerable firmware versions face direct risk of remote code execution without authentication, potentially compromising network perimeter security, intercepting traffic, or establishing persistent backdoors for lateral movement.
While this CVE lacks explicit MITRE ATT&CK mapping, Casky's AI-driven analysis would detect the exploitation patterns associated with buffer overflow attacks through detection of anomalous process behavior, memory corruption signals, and unauthorized code execution attempts. Practitioners using Casky would identify related ATT&CK techniques including T1190 (Exploit Public-Facing Application) for remote exploitation, T1547 (Boot or Logon Autostart Execution) if persistence mechanisms activate, and T1059 (Command and Scripting Interpreter) if shell access is established post-exploitation. The platform's 754 mapped security skills enable detection of malformed network requests targeting the formMapDelDevice endpoint, stack canary violations, unusual process spawning from network services, and firmware modification attempts—providing practitioners with granular visibility into attack progression from initial exploitation through post-compromise activities.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-36837. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation