Buffer Overflow Vulnerability in Totolink A3002MU Product
CVE-2026-90605
Key Information:
Badges
What is CVE-2026-90605?
A vulnerability exists in the Totolink A3002MU that allows an unauthorized remote attacker to exploit the formFilter function in the boa component. This occurs via a malformed IP address input, specifically targeting the ip6addr argument. Successful exploitation can lead to a buffer overflow condition, potentially allowing the attacker to execute arbitrary code or crash the affected device. This flaw has been publicly disclosed, emphasizing the importance of prompt action and remediation.
Affected Version(s)
A3002MU Hh-B20211125.1046
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
