{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/a3002mu-1.0.0-b20230403.1455/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:totolink:a3002mu_firmware:1.0.0-b20230403.1455:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-105284"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["A3002MU (1.0.0-B20230403.1455)"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","network-device","web-vulnerability","buffer-overflow","rce","edge-security"],"_cs_type":"threat","_cs_vendors":["Totolink"],"content_html":"\u003cp\u003eA critical authentication bypass vulnerability has been identified in the Totolink A3002MU wireless router, specifically affecting firmware version 1.0.0-B20230403.1455. The vulnerability resides within the function \u003ccode\u003esub_40FCFC\u003c/code\u003e located in the \u003ccode\u003e/bin/boa\u003c/code\u003e binary, which serves as the router's embedded web management interface.\u003c/p\u003e\n\u003cp\u003eThe flaw allows a remote, unauthenticated attacker to manipulate the authentication check process, resulting in improper authorization. Given that the web service runs with elevated privileges on the device, successful exploitation provides an attacker with administrative-level access to the router's configuration. A public exploit for this vulnerability is currently available, increasing the risk of in-the-wild exploitation. Defenders should restrict access to the web management interface to trusted network segments and monitor for anomalous HTTP traffic directed at the router's web server.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-105284 grants an attacker full administrative control over the Totolink A3002MU router. This allows for persistent configuration changes, traffic interception, potential credential harvesting, or the redirection of internal network traffic to attacker-controlled infrastructure. The vulnerability is rated with a CVSS 3.1 base score of 10.0, indicating the highest possible severity for impact to confidentiality, integrity, and availability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestrict access to the router web management interface (typically on port 80 or 443) to trusted internal management subnets via firewall rules or Access Control Lists (ACLs).\u003c/li\u003e\n\u003cli\u003eDisable remote web management from the WAN interface immediately to mitigate the risk of internet-based exploitation.\u003c/li\u003e\n\u003cli\u003eImplement monitoring on the perimeter or network segment to detect HTTP requests to the A3002MU management interface originating from non-authorized hosts.\u003c/li\u003e\n\u003cli\u003ePrioritize the isolation of these devices from the public internet while awaiting a vendor-supplied firmware update.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-05T11:39:17Z","date_published":"2026-10-05T09:39:21Z","id":"https://feed.craftedsignal.io/briefs/2026-10-totolink-auth-bypass/","summary":"The Totolink A3002MU router (v1.0.0-B20230403.1455) contains a critical authentication bypass vulnerability in the /bin/boa web server component, allowing remote unauthenticated access.","title":"Authentication Bypass in Totolink A3002MU via /bin/boa","url":"https://feed.craftedsignal.io/briefs/2026-10-totolink-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - A3002MU (1.0.0-B20230403.1455)","version":"https://jsonfeed.org/version/1.1"}