Junglewise Threat Intelligence

CVE-2026-90606: Totolink A3002MU buffer overflow in IPv6 setup

CVE-2026-90606 · Severity: critical · CVSS 9.9 · Published 2026-09-14

Technologies: TOTOLINK A3002MU. Vendors: TOTOLINK.

Executive brief

Totolink A3002MU is a wireless router used to provide internet connectivity for home and small office networks. A buffer overflow vulnerability in the router's web management interface allows a remote attacker to crash the web service by sending a specially crafted request with an excessively long IPv6 parameter, causing a denial of service and making the router inaccessible to administrators until reboot.

Technical details

A buffer overflow vulnerability exists in the formIpv6Setup function of the Boa web server component (/boafrm/formIpv6Setup endpoint) in Totolink A3002MU firmware Hh-B20211125.1046. The vulnerability is triggered when the static_ipv6 parameter is processed without proper length validation, allowing an attacker to overwrite adjacent memory. The attack is network-reachable and requires only network access to the router's web interface (no authentication bypass needed if the interface is accessible). A remote attacker can send a crafted POST request with an oversized static_ipv6 value to crash the Boa process, resulting in denial of service. The vulnerability has been publicly disclosed with proof-of-concept code available.

Affected products

  • Totolink A3002MU Hh-B20211125.1046

Timeline

  • 2026-09-14: disclosed: Vulnerability publicly disclosed with proof-of-concept
  • 2026-09-14: other: CVE-2026-90606 assigned

References

Related threats