Command Injection Vulnerability in Totolink A3002MU Router
CVE-2026-93742
Key Information:
Badges
What is CVE-2026-93742?
A command injection vulnerability has been identified in the Totolink A3002MU router specifically in the formWsc function located in the /boafrm/formWsc file. This weakness allows an attacker to manipulate the 'localPin' argument, leading to unauthorized command execution. The flaw is exploitable remotely, meaning that attackers can launch their exploits without needing physical access to the device. Public exploits are available, highlighting the urgency for users to implement necessary security measures.
Affected Version(s)
A3002MU Hh-B20211125.1046
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
