Junglewise Threat Intelligence

CVE-2026-93742: Totolink A3002MU command injection in formWsc

CVE-2026-93742 · Severity: critical · CVSS 9.9 · Published 2026-09-19

Technologies: TOTOLINK A3002MU. Vendors: TOTOLINK.

Executive brief

The Totolink A3002MU wireless router contains a command injection vulnerability in its web management interface that allows attackers to execute arbitrary commands on the device. An attacker can exploit this by sending a specially crafted request to the /boafrm/formWsc endpoint, potentially gaining full control of the router and compromising any networks or devices connected to it.

Technical details

A command injection vulnerability exists in the formWsc function of the /bin/boa web server where the localPin parameter is concatenated into a shell command without proper validation or escaping. An attacker can inject shell metacharacters through a POST request to /boafrm/formWsc to execute arbitrary commands with router privileges. The vulnerability requires network access to the router's management interface but no authentication.

Affected products

  • Totolink A3002MU Hh-B20211125.1046

Timeline

  • 2026-09-19: disclosed
  • 2026-09-19: exploited: public exploit available

References

Related threats