Description
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-09-13
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: potential remote code execution
Action: Immediate Patch
AI Analysis

Impact

A buffer overflow exists in the formFilter function of the boa component on the Totolink A3002MU router. Manipulating the ip6addr argument can overflow an internal buffer, which could allow an attacker to hijack program execution if the attacker controls the overflow. This potential for arbitrary code execution is inferred, as the CVE description does not explicitly confirm it. The vulnerability is classified as a stack-based buffer overflow (CWE-120) and a general buffer overrun (CWE-119), and it can lead to remote code execution, compromising confidentiality, integrity, and availability.

Affected Systems

The Totolink A3002MU router running firmware version Hh-B20211125.1046 is affected, specifically the formFilter function in the Boa component located at /boafrm/formFilter. No other vendors, products, or firmware revisions are reported to be impacted.

Risk and Exploitability

The CVSS score is 9.4, indicating critical severity. The EPSS score is less than 1%, indicating a very low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote; an attacker can trigger the flaw by sending a crafted ip6addr value to the vulnerable endpoint. Because the overflow corrupts the stack, a public exploit could lead to arbitrary code execution (inferred).

Generated by OpenCVE AI on September 15, 2026 at 16:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest firmware update from Totolink that resolves the formFilter buffer overflow
  • Limit access to the router’s management interface to trusted internal networks or a VPN, blocking public exposure of the /boafrm/formFilter endpoint
  • If a firmware update is not available, disable or restrict the Boa service and its formFilter endpoint to mitigate risk

Generated by OpenCVE AI on September 15, 2026 at 16:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Title Totolink A3002MU boa formFilter buffer overflow
First Time appeared Totolink
Totolink a3002mu
Weaknesses CWE-119
CWE-120
CPEs cpe:2.3:a:totolink:a3002mu:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a3002mu
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Totolink A3002mu
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:58:48.810Z

Reserved: 2026-09-12T19:30:28.764Z

Link: CVE-2026-90605

cve-icon Vulnrichment

Updated: 2026-09-15T13:49:15.231Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T00:16:57.447

Modified: 2026-09-15T14:17:22.863

Link: CVE-2026-90605

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:00:14Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')