Description
A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906. Affected by this issue is some unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. The manipulation leads to least privilege violation. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitation is known to be difficult.
Published: 2026-07-09
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the web interface component that manages the /etc/boa/boa.conf file allows an attacker to alter configuration settings and bypass the router’s least‑privilege model, effectively granting higher privileges and control over the device. The vulnerability is identified as CWE-266 (Improper Restriction of Component Permissions) and CWE-272 (Least Privilege Violation). The attack can be launched remotely through the router’s web management interface.

Affected Systems

Affected TOTOLINK routers include models A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 running firmware up to version 20260906; all devices with those models and firmware versions are potentially vulnerable.

Risk and Exploitability

The vulnerability has a CVSS severity score of 7.7, marking it as high. Its EPSS score is less than 1 percent, and it is not listed in the CISA KEV catalog. The attack vector is external via the web interface, but the exploit complexity is rated high and no public exploit is documented, indicating a moderate‑to‑high overall risk that warrants timely remediation.

Generated by OpenCVE AI on July 29, 2026 at 11:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from TOTOLINK for the affected router models.
  • Enforce strict file‑system permissions on /etc/boa/boa.conf so that only the root user can modify it.
  • Disable or restrict remote access to the web interface when it is not required or limit it to trusted networks.

Generated by OpenCVE AI on July 29, 2026 at 11:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink ac1200 T10
Vendors & Products Totolink ac1200 T10

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906. Affected by this issue is some unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. The manipulation leads to least privilege violation. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitation is known to be difficult.
Title TOTOLINK EX200 Web boa.conf least privilege violation
First Time appeared Totolink
Totolink a3000ru
Totolink a3100r
Totolink a950rg
Totolink ac1200t10
Totolink cp450
Totolink cs185r T10
Totolink ex200
Weaknesses CWE-266
CWE-272
CPEs cpe:2.3:a:totolink:a3000ru:*:*:*:*:*:*:*:*
cpe:2.3:a:totolink:a3100r:*:*:*:*:*:*:*:*
cpe:2.3:a:totolink:a950rg:*:*:*:*:*:*:*:*
cpe:2.3:a:totolink:ac1200t10:*:*:*:*:*:*:*:*
cpe:2.3:a:totolink:cp450:*:*:*:*:*:*:*:*
cpe:2.3:a:totolink:cs185r_t10:*:*:*:*:*:*:*:*
cpe:2.3:a:totolink:ex200:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a3000ru
Totolink a3100r
Totolink a950rg
Totolink ac1200t10
Totolink cp450
Totolink cs185r T10
Totolink ex200
References
Metrics cvssV2_0

{'score': 7.1, 'vector': 'AV:N/AC:H/Au:S/C:C/I:C/A:C/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Totolink A3000ru A3100r A950rg Ac1200 T10 Ac1200t10 Cp450 Cs185r T10 Ex200
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-10T13:37:52.501Z

Reserved: 2026-07-09T14:50:16.412Z

Link: CVE-2026-15271

cve-icon Vulnrichment

Updated: 2026-07-10T13:37:36.697Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:00:12Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-272

    Least Privilege Violation