CVE-2026-93739: Totolink A3002MU formWlAc buffer overflow
A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
Which deployments are known to be affected?
The affected product and firmware identified in the available data are Totolink A3002MU devices running Hh-B20211125.1046. The data does not establish whether other firmware versions or models are affected.
What access does an attacker need?
The attack can be performed remotely and requires low privileges. No user interaction is required according to the supplied severity vector.
Is exploit activity a practical concern?
Yes. A public exploit disclosure exists and may be used, which increases the likelihood of exploitation against reachable affected devices.