CVE-2026-105284: Totolink A3002MU Authentication Check boa sub_40FCFC improper authorization
A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
The affected product and version identified are Totolink A3002MU 1.0.0-B20230403.1455. The issue is in the Authentication Check component in /bin/boa.
Does exploitation require authentication or local access?
No. The vulnerability is remotely exploitable, and the supplied severity vector indicates no privileges or user interaction are required.
How serious is successful exploitation?
Successful manipulation can result in improper authorization. The supplied vector rates confidentiality, integrity, and availability impact as high, with scope changed.
Is exploit code available?
Yes. The vulnerability information states that a public exploit has been made available and could be used in attacks.