<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:o:totolink:a3002mu_firmware:1.0.0-B20230403.1455:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ototolinka3002mu_firmware1.0.0-b20230403.1455/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 09:39:21 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ototolinka3002mu_firmware1.0.0-b20230403.1455/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in Totolink A3002MU via /bin/boa</title><link>https://feed.craftedsignal.io/briefs/2026-10-totolink-auth-bypass/</link><pubDate>Mon, 05 Oct 2026 09:39:21 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-totolink-auth-bypass/</guid><description>The Totolink A3002MU router (v1.0.0-B20230403.1455) contains a critical authentication bypass vulnerability in the /bin/boa web server component, allowing remote unauthenticated access.</description><content:encoded><![CDATA[<p>A critical authentication bypass vulnerability has been identified in the Totolink A3002MU wireless router, specifically affecting firmware version 1.0.0-B20230403.1455. The vulnerability resides within the function <code>sub_40FCFC</code> located in the <code>/bin/boa</code> binary, which serves as the router's embedded web management interface.</p>
<p>The flaw allows a remote, unauthenticated attacker to manipulate the authentication check process, resulting in improper authorization. Given that the web service runs with elevated privileges on the device, successful exploitation provides an attacker with administrative-level access to the router's configuration. A public exploit for this vulnerability is currently available, increasing the risk of in-the-wild exploitation. Defenders should restrict access to the web management interface to trusted network segments and monitor for anomalous HTTP traffic directed at the router's web server.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-105284 grants an attacker full administrative control over the Totolink A3002MU router. This allows for persistent configuration changes, traffic interception, potential credential harvesting, or the redirection of internal network traffic to attacker-controlled infrastructure. The vulnerability is rated with a CVSS 3.1 base score of 10.0, indicating the highest possible severity for impact to confidentiality, integrity, and availability.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Restrict access to the router web management interface (typically on port 80 or 443) to trusted internal management subnets via firewall rules or Access Control Lists (ACLs).</li>
<li>Disable remote web management from the WAN interface immediately to mitigate the risk of internet-based exploitation.</li>
<li>Implement monitoring on the perimeter or network segment to detect HTTP requests to the A3002MU management interface originating from non-authorized hosts.</li>
<li>Prioritize the isolation of these devices from the public internet while awaiting a vendor-supplied firmware update.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>authentication-bypass</category><category>network-device</category><category>web-vulnerability</category><category>buffer-overflow</category><category>rce</category><category>edge-security</category></item></channel></rss>