Description
A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.
Published: 2026-09-14
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Buffer Overflow
Action: Immediate Patch
AI Analysis

Impact

A buffer overflow flaw exists in the formPortFw function of the Totolink A3002MU device firmware. The vulnerability is triggered by manipulating the service_type argument, allowing an attacker to overwrite memory and potentially execute arbitrary code‑bounds write, leading to control‑flow hijack and full compromise of the device. This vulnerability is a classic stack‑based buffer overflow (CWE‑119) and an instance of unsafe buffer handling (CWE‑120).

Affected Systems

The affected product is the Totolink A3002MU wireless router, firmware build Hh-B20211125.1046. No other vendors or versions are indicated.

Risk and Exploitability

The flaw has a CVSS score of 9.4, signalling critical severity. Security researchers have already published an exploit, and the vulnerability can be triggered remotely, likely through the router’s web interface, as inferred from the exploitation scenario. EPSS score is < 1%, but the publicly available exploit demonstrates that the attack is trivial to execute for a motivated actor. The issue is not listed in the CISA KEV catalog, yet its severity and remote nature warrant urgent action.

Generated by OpenCVE AI on September 15, 2026 at 15:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Verify whether a vendor firmware update that addresses the formPortFw buffer overflow is available, and apply it if published.
  • If an update is not currently available, block external access to the router’s management interface from untrusted networks using firewall rules or VLAN segmentation.
  • Limit the router’s exposure by disabling remote web management or replacing it with a secure management portal that enforces input validation and proper bounds checking.

Generated by OpenCVE AI on September 15, 2026 at 15:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.
Title Totolink A3002MU boa formPortFw buffer overflow
First Time appeared Totolink
Totolink a3002mu
Weaknesses CWE-119
CWE-120
CPEs cpe:2.3:a:totolink:a3002mu:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a3002mu
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Totolink A3002mu
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T14:36:08.294Z

Reserved: 2026-09-12T19:30:38.408Z

Link: CVE-2026-90608

cve-icon Vulnrichment

Updated: 2026-09-16T14:36:03.975Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T01:16:28.130

Modified: 2026-09-16T15:18:33.983

Link: CVE-2026-90608

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:45:19Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')