EXPOSURES › CVE-2026-93741
CVE-2026-93741
CRITICALTotolink A3002MU router firmware contains a remotely exploitable buffer overflow flaw that can be triggered via the submit-url argument.
The Totolink A3002MU router's formWlWds function in /boafrm/formWlWds suffers a buffer overflow when the submit-url argument is manipulated, allowing remote attackers to execute arbitrary code. This is a critical, actively exploitable vulnerability that compromises the device's integrity and could serve as an entry point for further attacks, including ransomware or data exfiltration. DIB organizations must ensure all network hardware, especially IoT and router devices, are patched and monitored for known exploits.
Shame score — A critical, remotely exploitable buffer overflow with a public exploit exists in a consumer router, indicating severe negligence in patching and secure coding practices.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.