Authentication Bypass in Totolink A3002MU via /bin/boa
The Totolink A3002MU router (v1.0.0-B20230403.1455) contains a critical authentication bypass vulnerability in the /bin/boa web server component, allowing remote unauthenticated access.
CVE search metadata
CVE search record: CVE-2026-105284. Severity: critical. CVSS: 10.0. KEV: no. Product: A3002MU (1.0.0-B20230403.1455). Brief: Authentication Bypass in Totolink A3002MU via /bin/boa. Brief link: https://feed.craftedsignal.io/briefs/2026-10-totolink-auth-bypass/
What's new
- 1. added coverage for A3002MU (1.0.0-B20230403.1455) Oct 5, 11:39 via nvd
A critical authentication bypass vulnerability has been identified in the Totolink A3002MU wireless router, specifically affecting firmware version 1.0.0-B20230403.1455. The vulnerability resides within the function sub_40FCFC located in the /bin/boa binary, which serves as the router's embedded web management interface.
The flaw allows a remote, unauthenticated attacker to manipulate the authentication check process, resulting in improper authorization. Given that the web service runs with elevated privileges on the device, successful exploitation provides an attacker with administrative-level access to the router's configuration. A public exploit for this vulnerability is currently available, increasing the risk of in-the-wild exploitation. Defenders should restrict access to the web management interface to trusted network segments and monitor for anomalous HTTP traffic directed at the router's web server.
Impact
Successful exploitation of CVE-2026-105284 grants an attacker full administrative control over the Totolink A3002MU router. This allows for persistent configuration changes, traffic interception, potential credential harvesting, or the redirection of internal network traffic to attacker-controlled infrastructure. The vulnerability is rated with a CVSS 3.1 base score of 10.0, indicating the highest possible severity for impact to confidentiality, integrity, and availability.
Recommendation
- Restrict access to the router web management interface (typically on port 80 or 443) to trusted internal management subnets via firewall rules or Access Control Lists (ACLs).
- Disable remote web management from the WAN interface immediately to mitigate the risk of internet-based exploitation.
- Implement monitoring on the perimeter or network segment to detect HTTP requests to the A3002MU management interface originating from non-authorized hosts.
- Prioritize the isolation of these devices from the public internet while awaiting a vendor-supplied firmware update.
Immediate actions
Disable WAN-side access to the Totolink web management interface
Mitigations
Restrict web management interface (port 80/443) access to authorized management subnets only
CVE-2026-105284