Description
A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.
Published: 2026-09-14
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A buffer overflow in the Boa formNewSchedule function of Totolink A3002MU router firmware Hh-B20211125.1046 allows an attacker that can manipulate the submit-url argument to overflow a buffer. The overflow can lead to arbitrary code execution on the device. The vulnerability is a classic uncontrolled buffer overflow as identified by CWE-119 and CWE-120.

Affected Systems

Manufactured by Totolink, the affected device is the A3002MU router running firmware version Hh-B20211125.1046. The flaw resides in the Boa web interface component exposed under /boafrm/formNewSchedule.

Risk and Exploitability

The CVSS score of 9.4 classifies this issue as critical, and the EPSS score is < 1%, indicating a very low but nonzero exploitation probability. The vulnerability is publicly documented and an exploit is known to be available. The attack can be performed from a remote host, implying that any external attacker who can reach the router’s web interface may target the flaw. The lack of a KEV listing does not reduce the urgency, as the exploit is openly shared and could be used in targeted or mass‑scale attacks.

Generated by OpenCVE AI on September 15, 2026 at 15:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware update from Totolink that addresses the boa formNewSchedule buffer overflow.
  • If a firmware patch is not yet available, block or disable access to the Boa web interface (e.g., by firewall rules or by configuring the router to accept Boa connections only from the local network).
  • Continuously monitor the router for abnormal requests to /boafrm/formNewSchedule and log any attempts to manipulate the submit-url parameter.

Generated by OpenCVE AI on September 15, 2026 at 15:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.
Title Totolink A3002MU boa formNewSchedule buffer overflow
First Time appeared Totolink
Totolink a3002mu
Weaknesses CWE-119
CWE-120
CPEs cpe:2.3:a:totolink:a3002mu:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a3002mu
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Totolink A3002mu
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T15:58:54.415Z

Reserved: 2026-09-12T19:30:35.161Z

Link: CVE-2026-90607

cve-icon Vulnrichment

Updated: 2026-09-14T15:57:55.224Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T01:16:27.870

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90607

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:45:19Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')