Description
A vulnerability was detected in Totolink A3002MU 1.0.0-B20230403.1455. This impacts the function sub_44B250 of the file /boafrm/formUploadFile of the component File Upload Handler. The manipulation of the argument filename results in path traversal. The attack can be executed remotely. The exploit is now public and may be used.
Published: 2026-10-05
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote File Write via path traversal
Action: Mitigate
AI Analysis

Impact

Totolink A3002MU routers expose a flaw in the File Upload Handler that allows an attacker to manipulate the filename parameter and perform a path traversal attack. The vulnerability is triggered by the sub_44B250 function within the /boafrm/formUploadFile component and can be exploited remotely through the web interface. By sending a crafted filename containing traversal characters, an attacker can cause files to be written or read from arbitrary locations on the device’s filesystem, which may lead to unauthorized configuration changes or further exploitation.

Affected Systems

The issue affects all A3002MU devices running firmware version 1.0.0-B20230403.1455. No other firmware versions have been identified as vulnerable at this time.

Risk and Exploitability

The CVSS score of 5.3 places this vulnerability in the medium severity range. However, the public availability of an exploit and the remote nature of the attack elevate the real‑world risk. The EPSS score is not provided, and the flaw is not listed in the CISA KEV catalog. Because the threat involves remote manipulation of file uploads, an attacker can potentially write arbitrary files to the router’s file system and then execute them, resulting in complete loss of confidentiality, integrity, and availability. The lack of an immediate patch maintains a high risk until a vendor update or workaround is enforced.

Generated by OpenCVE AI on October 5, 2026 at 10:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Disable or block the /boafrm/formUploadFile endpoint on all affected A3002MU routers.
  • Limit access to the device’s web interface to trusted IP ranges only, preventing remote upload attempts from the public network.
  • Update the router firmware to a version that includes a fix for the sub_44B250 path traversal, if such an update is available from Totolink.
  • Implement strict input validation for uploaded file names, rejecting any '..' or directory separators to mitigate path traversal (CWE-22).

Generated by OpenCVE AI on October 5, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Totolink A3002MU 1.0.0-B20230403.1455. This impacts the function sub_44B250 of the file /boafrm/formUploadFile of the component File Upload Handler. The manipulation of the argument filename results in path traversal. The attack can be executed remotely. The exploit is now public and may be used.
Title Totolink A3002MU File Upload formUploadFile sub_44B250 path traversal
First Time appeared Totolink
Totolink a3002mu
Weaknesses CWE-22
CPEs cpe:2.3:a:totolink:a3002mu:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a3002mu
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A3002mu
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T09:30:17.989Z

Reserved: 2026-10-04T22:18:20.743Z

Link: CVE-2026-105286

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T10:16:41.247

Modified: 2026-10-05T10:16:41.247

Link: CVE-2026-105286

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T11:00:16Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')