CVE-2026-93742: Totolink A3002MU formWsc command injection
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be initiated remotely and does not require user interaction. The supplied severity vector indicates that the attacker needs low-level privileges, so this is not described as an unauthenticated attack.
Which systems are known to be affected?
The affected product identified in the available information is Totolink A3002MU running firmware Hh-B20211125.1046. The vulnerable endpoint is /boafrm/formWsc, where the localPin argument is processed by formWsc.
Is public exploit code available?
Yes. The exploit has been made publicly available, increasing the likelihood that the issue could be used in attacks.