Executive brief
Totolink A3002MU is a wireless router used to provide internet connectivity for home and small office networks. A buffer overflow vulnerability in the router's web management interface allows a remote attacker to crash the web service by sending a specially crafted request with an excessively long IPv6 parameter, causing a denial of service and making the router inaccessible to administrators until reboot.
Technical details
A buffer overflow vulnerability exists in the formIpv6Setup function of the Boa web server component (/boafrm/formIpv6Setup endpoint) in Totolink A3002MU firmware Hh-B20211125.1046. The vulnerability is triggered when the static_ipv6 parameter is processed without proper length validation, allowing an attacker to overwrite adjacent memory. The attack is network-reachable and requires only network access to the router's web interface (no authentication bypass needed if the interface is accessible). A remote attacker can send a crafted POST request with an oversized static_ipv6 value to crash the Boa process, resulting in denial of service. The vulnerability has been publicly disclosed with proof-of-concept code available.
Affected products
- Totolink A3002MU Hh-B20211125.1046
Timeline
- 2026-09-14: disclosed: Vulnerability publicly disclosed with proof-of-concept
- 2026-09-14: other: CVE-2026-90606 assigned