Remote Buffer Overflow in Totolink A3002MU Router
A critical buffer overflow vulnerability in the Totolink A3002MU router allows unauthenticated remote attackers to trigger memory corruption via the /boafrm/formFilter endpoint.
CVE search metadata
CVE search record: CVE-2026-90605. Severity: critical. CVSS: 9.9. KEV: no. Product: A3002MU (Hh-B20211125.1046). Brief: Remote Buffer Overflow in Totolink A3002MU Router. Brief link: https://feed.craftedsignal.io/briefs/2026-09-totolink-buffer-overflow/
What's new
A critical buffer overflow vulnerability (CVE-2026-90605) has been identified in the Totolink A3002MU router running firmware version Hh-B20211125.1046. The flaw exists within the 'formFilter' function of the 'boa' web server component. An unauthenticated remote attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the '/boafrm/formFilter' URI, specifically by manipulating the 'ip6addr' argument. Successful exploitation of this buffer overflow may result in arbitrary code execution or a denial of service condition. Given that exploit code for this vulnerability is publicly available, organizations using the affected router models face an immediate risk of compromise. Defenders should prioritize restricting access to the management interface and monitoring for anomalous HTTP traffic targeting the vulnerable endpoint.
Impact
Successful exploitation of CVE-2026-90605 grants an attacker the ability to achieve remote code execution on the affected network device. This allows for complete compromise of the router, potentially enabling traffic interception, man-in-the-middle attacks, or persistent access to the internal network. The vulnerability poses a significant risk to consumer and small-office environments where this hardware is deployed.
Recommendation
- Block all external access to the web-based management interface of the Totolink A3002MU router at the firewall level.
- Implement network segmentation to isolate vulnerable network hardware from critical business infrastructure.
- Monitor ingress traffic to the '/boafrm/formFilter' endpoint for excessive payload lengths or suspicious characters within the 'ip6addr' argument.
Immediate actions
Restrict access to web management interface
Mitigations
Disable external web management interface access
CVE-2026-90605
Detection coverage 1
Detects CVE-2026-90607 Exploitation - Buffer Overflow via /boafrm/formNewSchedule
criticalDetects exploitation attempts against the formNewSchedule function by monitoring POST requests to the vulnerable path.
Detection queries are available on the platform. Get full rules →