Executive brief
The Totolink A3002MU wireless router contains a memory corruption vulnerability in its web management interface. An unauthenticated attacker on the network can send a specially crafted HTTP request to crash the router's web server and temporarily take the device offline, preventing legitimate users from accessing management functions or internet connectivity.
Technical details
A buffer overflow vulnerability exists in the /bin/boa web server's formFilter function, specifically in the handling of the ip6addr parameter. The vulnerable code uses unsafe string-copy operations (strcpy) without proper length validation, allowing an attacker to send an oversized IPv6 address value via POST request to /boafrm/formFilter. No authentication is required; the attack vector is purely network-based. Successful exploitation overwrites adjacent memory and crashes the Boa process, resulting in denial of service. A proof-of-concept exploit has been publicly disclosed.
Affected products
- Totolink A3002MU Hh-B20211125.1046
Timeline
- 2026-09-14: disclosed: CVE-2026-90605 published; exploit proof-of-concept made public