CVE-2026-93740: Totolink A3002MU formWlEncrypt buffer overflow
Published Sep 18, 2026
·Updated
A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Affected Software
1 affected component
TOTOLINK A3002MU=Hh-B20211125.1046
Event History
Sep 18, 2026
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which systems are affected?
The affected product identified is Totolink A3002MU running firmware Hh-B20211125.1046. The vulnerable handler is /boafrm/formWlEncrypt.
2
What does an attacker need to exploit this issue?
An attacker can initiate the attack remotely by manipulating the submit-url argument handled by formWlEncrypt. No privileges or user interaction are indicated in the provided severity vector.
3
Is exploit code available?
Yes. The available information states that a public exploit exists and might be used.