CVE-2026-90608: Totolink A3002MU boa formPortFw buffer overflow
Published Sep 14, 2026
·Updated
A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument servicetype causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.
Affected Software
1 affected component
TOTOLINK A3002MU=Hh-B20211125.1046
Event History
Sep 14, 2026
CVE Published
via MITRE·12:15 AM
Data Sourced
via MITRE·12:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attack can be initiated remotely and does not require user interaction. The vector indicates that low privileges are required, so exploitation is not described as unauthenticated.
2
Which device version is identified as affected?
The affected product identified is the TOTOLINK A3002MU running Hh-B20211125.1046.
3
Is exploit code available?
Yes. The available data states that an exploit has been published and may be used.