EXPOSURES › CVE-2026-93742
CVE-2026-93742
CRITICALTotolink A3002MU router firmware allows remote command injection via unvalidated user input in the formWsc function.
An attacker can remotely execute arbitrary commands on the Totolink A3002MU router by manipulating the localPin argument in the formWsc function of /boafrm/formWsc. This is a critical unpatched vulnerability that enables remote code execution, allowing attackers to pivot into networks, deploy ransomware, or steal credentials. DIB organizations must ensure all network hardware, especially IoT and router firmware, is patched and monitored for known exploits.
Shame score — A critical remote code execution vulnerability in consumer router firmware was publicly exploited, demonstrating severe negligence in patching and input validation for network infrastructure.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.