CVE-2026-90604: Totolink A3002MU Anchor Tag cross site scripting
Published Sep 13, 2026
·Updated
A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Affected Software
1 affected component
TOTOLINK A3002MU=Hh-B20211125.1046
Event History
Sep 13, 2026
CVE Published
via MITRE·11:15 PM
Data Sourced
via MITRE·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access and interaction are required to exploit this issue?
The vector is remote and the attack complexity is low, but the attacker requires low-level privileges and user interaction. The available data does not identify the specific privileged account or interaction required.
2
Which device version is identified as affected?
The issue is reported in Totolink A3002MU firmware Hh-B20211125.1046. No other versions or products are identified in the available data.
3
Is exploitation only theoretical?
No. A public exploit has been released and may be used in attacks.