Junglewise Threat Intelligence

CVE-2026-93738: Totolink A3002MU buffer overflow in formSchedule

CVE-2026-93738 · Severity: critical · CVSS 9.9 · Published 2026-09-18

Technologies: TOTOLINK A3002MU. Vendors: TOTOLINK.

Executive brief

The Totolink A3002MU wireless router contains a buffer overflow vulnerability in its web management interface. An attacker can remotely send a specially crafted HTTP request to crash the web server, causing the router to become unresponsive and unable to be managed. The vulnerability can be exploited over the network without requiring authentication, and proof-of-concept code has been publicly released.

Technical details

A buffer overflow exists in the /boafrm/formSchedule endpoint of the Boa web server, where the webpage parameter is copied into a fixed-size buffer without proper length validation. An attacker can send an HTTP POST request with an oversized webpage parameter value to overflow the buffer and corrupt adjacent memory, crashing the Boa process. This results in denial of service, preventing legitimate access to the router's management interface.

Affected products

  • Totolink A3002MU Hh-B20211125.1046

Timeline

  • 2026-09-18: disclosed
  • other: Public exploit published

References

Related threats