Description
A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
Published: 2026-09-13
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A buffer overflow exists in the formIpv6Setup function of the A3002MU router’s boa component. By sending a crafted static_ipv6 argument, an attacker can overflow the buffer, possibly executing arbitrary code. The flaw is actively exploitable remotely, with publicly disclosed exploits available.

Affected Systems

The vulnerability affects the Totolink A3002MU model, firmware version Hh‑B20211125.1046. No other models or firmware versions are listed as affected.

Risk and Exploitability

The CVSS score of 9.4 indicates critical severity. The EPSS score is < 1% (approximately 0.005), reflecting a very low but nonzero exploitation probability. The existence of public exploits and remote attack feasibility suggests a high likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. An attacker can trigger the overflow by targeting the formIpv6Setup endpoint from outside the device, using a crafted static_ipv6 payload, leading potentially to remote code execution.

Generated by OpenCVE AI on September 15, 2026 at 16:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s latest firmware update to patch the formIpv6Setup buffer overflow.
  • If a firmware upgrade is not yet available, block or filter external traffic to the formIpv6Setup endpoint using firewall or access control lists.
  • Restrict management interface access to trusted local networks only, disabling remote management interfaces.

Generated by OpenCVE AI on September 15, 2026 at 16:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
Title Totolink A3002MU boa formIpv6Setup buffer overflow
First Time appeared Totolink
Totolink a3002mu
Weaknesses CWE-119
CWE-120
CPEs cpe:2.3:a:totolink:a3002mu:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a3002mu
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Totolink A3002mu
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T18:07:33.379Z

Reserved: 2026-09-12T19:30:31.852Z

Link: CVE-2026-90606

cve-icon Vulnrichment

Updated: 2026-09-15T18:07:29.175Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T00:16:57.617

Modified: 2026-09-15T19:17:46.067

Link: CVE-2026-90606

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:30:11Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')