CVE-2026-90605
nicheRemote Buffer Overflow in Totolink A3002MU Router formFilter (boa)
A remote buffer overflow (CWE-119/CWE-120) exists in the boa web server component of the Totolink A3002MU router, specifically in the formFilter function reachable via the /boafrm/formFilter endpoint. An attacker triggers the flaw by sending an overly long or malformed value in the ip6addr argument, which is not properly length-checked before being copied into a fixed-size buffer. Successful exploitation occurs over the network with low privileges required (per the CVSS 4.0 vector, PR:L) and can crash the device or potentially achieve code execution, compromising the router's confidentiality, integrity, and availability. Only firmware version Hh-B20211125.1046 is listed as affected. The vulnerability record states an exploit has been made available publicly, though no separate proof-of-concept is currently tracked, and there is no evidence of active exploitation (not in CISA KEV).
What to do: Check for and apply the latest Totolink firmware for the A3002MU, as only Hh-B20211125.1046 is confirmed affected and no fixed version is documented yet. Immediately disable remote/WAN-side administration of the router's web interface so the /boafrm/formFilter endpoint is not reachable from the internet, and restrict management access to the LAN. Monitor device logs and uptime for unexpected reboots or crashes, which could indicate exploitation attempts.
| Totolink A3002MU | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
- Weakness
- CWE-119, CWE-120
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.