ZeroHour

CVE-2026-90606

niche

Buffer Overflow in TOTOLINK A3002RU-class Router A3002MU IPv6 Setup Handler (boa)

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

The TOTOLINK A3002MU router, firmware version Hh-B20211125.1046, contains a buffer overflow (CWE-119/120) in the formIpv6Setup function of the embedded boa web server, reachable via the /boafrm/formIpv6Setup endpoint. A remote attacker triggers the flaw by sending an excessively long value in the static_ipv6 parameter of an IPv6 configuration request; the CVSS vector indicates low privileges are required, so the attacker likely needs to be authenticated to the router's admin interface. Successful exploitation can crash or fully compromise the device, with high impact to confidentiality, integrity, and availability of both the router and subsequent systems that depend on it. Anyone running this specific A3002MU firmware version — typically home or small-office users with the management interface reachable — is affected. The entry notes the exploit has been disclosed publicly (CVSS E:P), but no active exploitation in the wild is known and the flaw is not on the CISA KEV list.

What to do: Check TOTOLINK's support site for a firmware update for the A3002MU and apply it if one exists; if no patch is available, disable WAN-side/remote administration so the boa interface is reachable only from the LAN, change default admin credentials (since exploitation appears to require authentication), and consider retiring the device. Monitor device logs or upstream firewalls for requests to /boafrm/formIpv6Setup containing abnormally long static_ipv6 values.

Affected
TOTOLINK A3002MU
Estimated exposure
nichelikely hundreds to low thousands of internet-exposed devices — TOTOLINK routers in aggregate appear in public internet scans in the tens of thousands, but the A3002MU is an older niche model, so only a small fraction of that fleet is plausibly exposed; this is an estimate without a model-specific scan…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

Weakness
CWE-119, CWE-120
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.