rootpwn

critical · CVSS v3 10 · CVSS v4 10 · EPSS 0.00644

CVE-2026-93741

A critical stack-based buffer overflow vulnerability exists in the Totolink A3002MU router firmware within the formWlWds function. Specifica

Overview

A critical stack-based buffer overflow vulnerability exists in the Totolink A3002MU router firmware within the formWlWds function. Specifically, improper handling of the submit-url parameter in requests to the /boafrm/formWlWds endpoint allows remote attackers to trigger memory corruption. This matters because successful exploitation could lead to arbitrary code execution or complete device compromise without authentication.

Description

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

Impact

This vulnerability impacts the Confidentiality, Integrity, and Availability of the affected network device. An unauthenticated remote attacker could achieve complete system compromise, potentially hijacking network traffic or using the router as a pivot point. Home and small office users operating the vulnerable firmware version are directly at risk.

Remediation

Apply the official vendor firmware patch if available to resolve the underlying buffer overflow condition. If a patch is not available, restrict management access to trusted internal networks only and disable remote administration interfaces. Monitor network perimeter logs for anomalous HTTP requests targeting the affected URI.

Risk context

The vulnerability carries a maximum CVSS v3 and v4 score of 10.0, indicating extreme severity. While the current EPSS score is relatively low at 0.00644, the existence of public exploit material elevates the operational urgency for defenders to secure exposed devices immediately.

Affected products

  • Totolink A3002MU Hh-B20211125.1046

Scores

Severity
critical
CVSS v2
10
CVSS v3
10
CVSS v4
10
EPSS
0.00644

buffer-overflow remote-code-execution router-vulnerability totolink critical-severity iot-security

← All CVEs