Description
A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-10-05
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access via Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

A flaw in the authentication check routine of the Totolink A3002MU firmware allows an attacker to manipulate input to the sub_40FCFC function within the /bin/boa component, resulting in improper authorization. The vulnerability permits an adversary to bypass normal authentication and gain unauthorized access to the device, potentially enabling further exploitation of the firmware. The description indicates that the flaw can be triggered remotely and has been made publicly available. Consequently, an attacker could obtain control or sensitive information without proper authentication. This weakness is classified under CWE-266 (Missing Authorization) and CWE-285 (Improper Authorization) and carries a CVSS score of 10.

Affected Systems

The affected product is the Totolink A3002MU router, current firmware version 1.0.0-B20230403.1455. No other versions or products are listed as impacted.

Risk and Exploitability

Because the flaw can be exploited from a remote source and a public exploit exists, the risk is high. The CVSS score of 10 emphasizes the critical severity. The EPSS score is not available, but the lack of KEV listing does not diminish the threat, as public knowledge and exploitation code are present. The attack vector is likely remote, potentially from the internet or an internal network that can reach the router's management interface. An attacker with the ability to reach the device could abuse this weakness to achieve unauthorized access and further lateral movement.

Generated by OpenCVE AI on October 5, 2026 at 10:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware update from Totolink that addresses the authentication check flaw.
  • If an immediate update is not possible, limit remote access to the router by disabling WAN‑side management or restricting it to trusted IP ranges.
  • Isolate the router from critical network segments and monitor for suspicious access attempts.

Generated by OpenCVE AI on October 5, 2026 at 10:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Title Totolink A3002MU Authentication Check boa sub_40FCFC improper authorization
First Time appeared Totolink
Totolink a3002mu
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:totolink:a3002mu:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a3002mu
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 10, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Totolink A3002mu
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T15:29:02.936Z

Reserved: 2026-10-04T22:17:45.310Z

Link: CVE-2026-105284

cve-icon Vulnrichment

Updated: 2026-10-05T15:19:30.699Z

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:12.350

Modified: 2026-10-05T16:17:12.020

Link: CVE-2026-105284

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T11:15:07Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-285

    Improper Authorization