critical · CVSS v3 9.9 · CVSS v4 9.4 · EPSS 0.0188
CVE-2026-93742
A critical command injection vulnerability exists within the formWsc function of the Totolink A3002MU firmware. The flaw stems from improper
Overview
A critical command injection vulnerability exists within the formWsc function of the Totolink A3002MU firmware. The flaw stems from improper sanitization of the localPin argument processed via the /boafrm/formWsc endpoint. Remote attackers can leverage this vulnerability to execute arbitrary commands on the underlying operating system.
Description
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Impact
Successful exploitation grants an unauthorized remote attacker complete administrative control over the affected router, resulting in a total compromise of confidentiality, integrity, and availability (CIA triad). Organizations utilizing this device risk full network exposure, traffic interception, and potential lateral movement into trusted internal segments.
Remediation
Apply the latest available vendor firmware updates or patches provided by Totolink to resolve the underlying command injection flaw. If patches are unavailable, restrict administrative access to trusted internal management interfaces and disable remote management entirely. Implement network segmentation and monitoring to detect anomalous traffic targeting the vulnerable endpoint.
Risk context
The vulnerability carries a critical severity rating with a CVSS v3 score of 9.9 and a CVSS v4 score of 9.4, indicating extreme risk due to ease of remote exploitation. The current EPSS score of 0.0188 combined with public exploit availability requires immediate prioritization of mitigation steps for any exposed legacy devices.
Affected products
- Totolink A3002MU
Scores
- Severity
- critical
- CVSS v2
- 9
- CVSS v3
- 9.9
- CVSS v4
- 9.4
- EPSS
- 0.0188