Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-93741: Totolink A3002MU remote buffer overflow via submit URL
CVE-2026-93741 · published 10 days ago
Summary
The Totolink A3002MU router can be tricked into overflowing memory when a specially crafted web request is sent to its configuration page. This could let an attacker take control of the device from anywhere on the internet. Update the router firmware to the latest version or disable remote access to the web interface until a fix is applied.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| totolink | a3002mu | Hh-B20211125.1046 |
Original advisory text
Totolink A3002MU formWlWds buffer overflow
A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Severity
9.3
Critical
CVSS 2.0: 10.0 (NVD)
CVSS 3.1: 10.0 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-119Buffer Overflow
CWE-120Classic Buffer Overflow
Timeline
Published19 Sep 2026
Updated28 Sep 2026
First seen19 Sep 2026
Track software like this
Free during beta