Skip to content
Threat Feed
critical advisory

Remote Buffer Overflow in Totolink A3002MU Router

A critical buffer overflow vulnerability in the Totolink A3002MU router allows unauthenticated remote attackers to trigger memory corruption via the /boafrm/formFilter endpoint.

CVE search metadata

CVE search record: CVE-2026-90605. Severity: critical. CVSS: 9.9. KEV: no. Product: A3002MU (Hh-B20211125.1046). Brief: Remote Buffer Overflow in Totolink A3002MU Router. Brief link: https://feed.craftedsignal.io/briefs/2026-09-totolink-buffer-overflow/

What's new

  • 1. added coverage for A3002MU (Hh-B20211125.1046) Sep 14, 01:29 via nvd
  • 2. added detection rule: Detects CVE-2026-90607 Exploitation - Buffer Overflow via /boafrm/formNewSchedule Sep 14, 01:28 via nvd

A critical buffer overflow vulnerability (CVE-2026-90605) has been identified in the Totolink A3002MU router running firmware version Hh-B20211125.1046. The flaw exists within the 'formFilter' function of the 'boa' web server component. An unauthenticated remote attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the '/boafrm/formFilter' URI, specifically by manipulating the 'ip6addr' argument. Successful exploitation of this buffer overflow may result in arbitrary code execution or a denial of service condition. Given that exploit code for this vulnerability is publicly available, organizations using the affected router models face an immediate risk of compromise. Defenders should prioritize restricting access to the management interface and monitoring for anomalous HTTP traffic targeting the vulnerable endpoint.

Impact

Successful exploitation of CVE-2026-90605 grants an attacker the ability to achieve remote code execution on the affected network device. This allows for complete compromise of the router, potentially enabling traffic interception, man-in-the-middle attacks, or persistent access to the internal network. The vulnerability poses a significant risk to consumer and small-office environments where this hardware is deployed.

Recommendation

  1. Block all external access to the web-based management interface of the Totolink A3002MU router at the firewall level.
  2. Implement network segmentation to isolate vulnerable network hardware from critical business infrastructure.
  3. Monitor ingress traffic to the '/boafrm/formFilter' endpoint for excessive payload lengths or suspicious characters within the 'ip6addr' argument.

Immediate actions

Restrict access to web management interface

IT Operations 24h

Mitigations

Disable external web management interface access

immediate IT Operations

CVE-2026-90605

Detection coverage 1

Detects CVE-2026-90607 Exploitation - Buffer Overflow via /boafrm/formNewSchedule

critical

Detects exploitation attempts against the formNewSchedule function by monitoring POST requests to the vulnerable path.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →