Description
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-09-19
Score: 9.4 Critical
EPSS: 2.3% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A command injection flaw exists in the formWsc function within the /boafrm/formWsc file of the Totolink A3002MU router. By manipulating the localPin argument, a remote attacker can inject arbitrary shell commands for execution. The vulnerability is a classic example of CWE-74 (Incorrect Parsing of Argument String) and CWE-77 (Improper Validation or Sanitization of Input). Successful exploitation would give the attacker complete control over the device, allowing data exfiltration, network pivoting, or further compromise of connected systems.

Affected Systems

The affected device is the Totolink A3002MU model, specifically firmware builds including Hh-B20211125.1046. No other vendor or product variants are listed as impacted.

Risk and Exploitability

The CVSS score of 9.4 classifies this flaw as Critical, and the EPSS score of 3% indicates a low‑to‑moderate likelihood of exploitation in the wild. The vulnerability is not registered in the CISA KEV catalog, yet public exploit code has already been posted, so a determined adversary can readily craft an attack. The attack vector is remote, requiring only network connectivity to the router’s web management interface, and no local privileges are needed.

Generated by OpenCVE AI on September 25, 2026 at 01:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the A3002MU firmware to the latest version that fixes the formWsc command injection flaw.
  • Disable or restrict remote access to the router’s management interface or place it behind a VPN or firewall and limit access to trusted IPs.
  • Monitor device logs and network traffic for suspicious command‑execution activity and anomalies on the localPin parameter.

Generated by OpenCVE AI on September 25, 2026 at 01:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Title Totolink A3002MU formWsc command injection
First Time appeared Totolink
Totolink a3002mu
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:totolink:a3002mu:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a3002mu
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Totolink A3002mu
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T18:28:19.220Z

Reserved: 2026-09-18T15:43:51.231Z

Link: CVE-2026-93742

cve-icon Vulnrichment

Updated: 2026-09-21T18:28:13.587Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T09:16:34.740

Modified: 2026-09-21T19:17:17.273

Link: CVE-2026-93742

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T01:45:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')