Description
A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Published: 2026-09-13
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

This vulnerability occurs in the anchor tag handler of the Totolink A3002MU device. Malicious input can be crafted to inject arbitrary JavaScript into the web interface, enabling an attacker to run code in the context of the victim’s browser. The flaw is a classic cross‑site scripting weakness (CWE‑79) combined with a code‑execution capability in the handler (CWE‑94). Remote attackers can trigger the flaw by sending specially formatted requests to the device’s management interface, and the publicly released exploit demonstrates that the attack can be performed over the network without additional credentials.

Affected Systems

Affected is the Totolink A3002MU router running firmware image Hh-B20211125.1046. The vulnerable component is the Anchor Tag Handler; no other product variants are listed as impacted.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity, while the EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring only network access to the device’s web interface. Because the flaw allows arbitrary script injection, an attacker could steal credentials, hijack sessions, or redirect users to malicious sites, thereby compromising confidentiality and integrity of the device’s configuration.

Generated by OpenCVE AI on September 15, 2026 at 16:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the device firmware to the latest version that removes the vulnerable anchor tag handler.
  • If a firmware update is unavailable, configure a firewall or content filter to block or sanitize malicious payloads targeting the Anchor Tag Handler endpoint.
  • Continuously monitor the device’s web interface for signs of cross‑site scripting activity and restrict non‑essential administrative access to reduce attack surface.

Generated by OpenCVE AI on September 15, 2026 at 16:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Title Totolink A3002MU Anchor Tag cross site scripting
First Time appeared Totolink
Totolink a3002mu
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:totolink:a3002mu:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a3002mu
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A3002mu
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T15:21:21.405Z

Reserved: 2026-09-12T19:30:25.526Z

Link: CVE-2026-90604

cve-icon Vulnrichment

Updated: 2026-09-14T15:21:13.799Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T00:16:57.280

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90604

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:30:11Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')