ZeroHour

CVE-2026-90605

niche

Remote Buffer Overflow in Totolink A3002MU Router formFilter (boa)

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

A remote buffer overflow (CWE-119/CWE-120) exists in the boa web server component of the Totolink A3002MU router, specifically in the formFilter function reachable via the /boafrm/formFilter endpoint. An attacker triggers the flaw by sending an overly long or malformed value in the ip6addr argument, which is not properly length-checked before being copied into a fixed-size buffer. Successful exploitation occurs over the network with low privileges required (per the CVSS 4.0 vector, PR:L) and can crash the device or potentially achieve code execution, compromising the router's confidentiality, integrity, and availability. Only firmware version Hh-B20211125.1046 is listed as affected. The vulnerability record states an exploit has been made available publicly, though no separate proof-of-concept is currently tracked, and there is no evidence of active exploitation (not in CISA KEV).

What to do: Check for and apply the latest Totolink firmware for the A3002MU, as only Hh-B20211125.1046 is confirmed affected and no fixed version is documented yet. Immediately disable remote/WAN-side administration of the router's web interface so the /boafrm/formFilter endpoint is not reachable from the internet, and restrict management access to the LAN. Monitor device logs and uptime for unexpected reboots or crashes, which could indicate exploitation attempts.

Affected
Totolink A3002MU
Estimated exposure
nichelikely on the order of a few thousand internet-exposed devices (estimate) — The A3002MU is a consumer-grade router with limited regional distribution, and public internet scan data for Totolink boa-based admin interfaces typically shows exposures in the low thousands rather than tens of thousands.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

Weakness
CWE-119, CWE-120
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.