CVE-2026-90606
nicheBuffer Overflow in TOTOLINK A3002RU-class Router A3002MU IPv6 Setup Handler (boa)
The TOTOLINK A3002MU router, firmware version Hh-B20211125.1046, contains a buffer overflow (CWE-119/120) in the formIpv6Setup function of the embedded boa web server, reachable via the /boafrm/formIpv6Setup endpoint. A remote attacker triggers the flaw by sending an excessively long value in the static_ipv6 parameter of an IPv6 configuration request; the CVSS vector indicates low privileges are required, so the attacker likely needs to be authenticated to the router's admin interface. Successful exploitation can crash or fully compromise the device, with high impact to confidentiality, integrity, and availability of both the router and subsequent systems that depend on it. Anyone running this specific A3002MU firmware version — typically home or small-office users with the management interface reachable — is affected. The entry notes the exploit has been disclosed publicly (CVSS E:P), but no active exploitation in the wild is known and the flaw is not on the CISA KEV list.
What to do: Check TOTOLINK's support site for a firmware update for the A3002MU and apply it if one exists; if no patch is available, disable WAN-side/remote administration so the boa interface is reachable only from the LAN, change default admin credentials (since exploitation appears to require authentication), and consider retiring the device. Monitor device logs or upstream firewalls for requests to /boafrm/formIpv6Setup containing abnormally long static_ipv6 values.
| TOTOLINK A3002MU | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
- Weakness
- CWE-119, CWE-120
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.