ZeroHour

CVE-2026-90608

moderate

Remote Buffer Overflow in TOTOLINK A3002MU formPortFw via service_type

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

TOTOLINK's A3002MU router, firmware Hh-B20211125.1046, contains a remotely exploitable buffer overflow (CWE-119/CWE-120) in the formPortFw function of the embedded boa web server, reachable through the /boafrm/formPortFw endpoint that handles port-forwarding configuration. An attacker triggers the flaw by supplying an oversized or malformed service_type argument to that endpoint; the CVSS 4.0 vector (AV:N/AC:L/PR:L) indicates this requires only low-privileged access, which on TOTOLINK devices frequently means any authenticated session, including default or weak admin credentials. A successful overflow can corrupt memory and potentially yield arbitrary code execution on the router, with high impact on the device's confidentiality, integrity, and availability. Owners of the A3002MU running the affected firmware are at risk, particularly devices whose web management interface is reachable from the internet. The vuldb description states an exploit may have been published, but no public PoC is confirmed and there is no evidence of in-the-wild exploitation or a CISA KEV listing at this time.

What to do: Immediately restrict access to the router's web management interface so it is only reachable from the LAN, and never forward the admin UI to the internet; change any default admin credentials. Check the device's port-forwarding table for unexpected entries and reboot/re-flash if tampering is suspected. Monitor TOTOLINK's official support site for a firmware update for the A3002MU and apply it as soon as one is released, as no fixed version is listed in the current data.

Affected
TOTOLINK A3002MU
Estimated exposure
moderate≈ low thousands of internet-exposed A3002MU devices (estimate) — TOTOLINK is a budget consumer-router vendor whose boa-based management interfaces commonly appear in internet scans in the tens of thousands; this specific, dated model is likely a small fraction of that, plausibly in the low thousands —…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.

Weakness
CWE-119, CWE-120
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.