Path Traversal Vulnerability in Totolink A3002MU Product
CVE-2026-105286
Key Information:
Badges
What is CVE-2026-105286?
A vulnerability has been identified in the Totolink A3002MU product, specifically in the File Upload Handler's function sub_44B250. This issue allows for path traversal due to improper handling of the 'filename' argument, enabling attackers to remotely manipulate file uploads. The flaw is now publicly exploitable, posing significant risks to device integrity and user data. Users are strongly advised to implement security measures to mitigate potential attacks.
Affected Version(s)
A3002MU 1.0.0-B20230403.1455
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
