Junglewise Threat Intelligence

CVE-2026-90605: Totolink A3002MU buffer overflow in formFilter

CVE-2026-90605 · Severity: critical · CVSS 9.9 · Published 2026-09-14

Technologies: TOTOLINK A3002MU. Vendors: TOTOLINK.

Executive brief

The Totolink A3002MU wireless router contains a memory corruption vulnerability in its web management interface. An unauthenticated attacker on the network can send a specially crafted HTTP request to crash the router's web server and temporarily take the device offline, preventing legitimate users from accessing management functions or internet connectivity.

Technical details

A buffer overflow vulnerability exists in the /bin/boa web server's formFilter function, specifically in the handling of the ip6addr parameter. The vulnerable code uses unsafe string-copy operations (strcpy) without proper length validation, allowing an attacker to send an oversized IPv6 address value via POST request to /boafrm/formFilter. No authentication is required; the attack vector is purely network-based. Successful exploitation overwrites adjacent memory and crashes the Boa process, resulting in denial of service. A proof-of-concept exploit has been publicly disclosed.

Affected products

  • Totolink A3002MU Hh-B20211125.1046

Timeline

  • 2026-09-14: disclosed: CVE-2026-90605 published; exploit proof-of-concept made public

References

Related threats