CVE-2026-90607: Totolink A3002MU boa formNewSchedule buffer overflow
Published Sep 14, 2026
·Updated
A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.
Affected Software
2 affected components
TOTOLINK A3002MU=Hh-B20211125.1046
boa=
Event History
Sep 14, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The attack is remote and requires low privileges. No user interaction is required.
2
How can I identify potentially affected devices?
The reported affected product is the Totolink A3002MU running Hh-B20211125.1046, with the boa component exposing the /boafrm/formNewSchedule functionality.
3
Is exploitation likely to be practical?
A public exploit is available, and the vulnerability is rated critical with high impacts to confidentiality, integrity, and availability.