Cross Site Scripting Vulnerability in Totolink A3002MU
CVE-2026-90604
Key Information:
Badges
What is CVE-2026-90604?
A security flaw has been identified within the Totolink A3002MU Hh-B20211125.1046, specifically affecting the component known as the Anchor Tag Handler. This vulnerability enables attackers to manipulate inputs, leading to potential cross site scripting (XSS) attacks. The flaw allows remote exploitation, which may facilitate malicious activities, especially since the exploit details have been made publicly available, increasing the risk of widespread attacks on affected systems.
Affected Version(s)
A3002MU Hh-B20211125.1046
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
