Junglewise Threat Intelligence

CVE-2026-90604: Totolink A3002MU cross-site scripting in web interface

CVE-2026-90604 · Severity: low · CVSS 3.5 · Published 2026-09-14

Technologies: TOTOLINK A3002MU. Vendors: TOTOLINK.

Executive brief

The Totolink A3002MU wireless router is vulnerable to cross-site scripting (XSS) in its web-based management interface. An attacker can craft a malicious URL that, when opened by an authenticated administrator, executes arbitrary JavaScript code in the browser. This can allow the attacker to steal the administrator's session credentials and take control of the router's configuration.

Technical details

A reflected XSS vulnerability exists in multiple pages of the Totolink A3002MU web interface (portfw.htm, reboot.htm, arptbl.htm, etc.). The vulnerability stems from insufficient validation and escaping of URL fragment content (#), which is directly passed to eval() function execution. The attack requires the victim to be already authenticated to the router's management interface and to click a malicious link. An attacker can craft URLs containing arbitrary JavaScript that will execute in the authenticated context, enabling session token theft and other actions. The vulnerability affects firmware version Hh-B20211125.1046 and has public exploit code available.

Affected products

  • Totolink A3002MU Hh-B20211125.1046

Timeline

  • 2026-09-14: disclosed
  • other: Public exploit code available

References

Related threats