{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/a3002mu-hh-b20211125.1046/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:totolink:a3002mu_firmware:hh-b20211125.1046:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-90605"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["A3002MU (Hh-B20211125.1046)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Totolink"],"content_html":"\u003cp\u003eA critical buffer overflow vulnerability (CVE-2026-90605) has been identified in the Totolink A3002MU router running firmware version Hh-B20211125.1046. The flaw exists within the 'formFilter' function of the 'boa' web server component. An unauthenticated remote attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the '/boafrm/formFilter' URI, specifically by manipulating the 'ip6addr' argument. Successful exploitation of this buffer overflow may result in arbitrary code execution or a denial of service condition. Given that exploit code for this vulnerability is publicly available, organizations using the affected router models face an immediate risk of compromise. Defenders should prioritize restricting access to the management interface and monitoring for anomalous HTTP traffic targeting the vulnerable endpoint.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-90605 grants an attacker the ability to achieve remote code execution on the affected network device. This allows for complete compromise of the router, potentially enabling traffic interception, man-in-the-middle attacks, or persistent access to the internal network. The vulnerability poses a significant risk to consumer and small-office environments where this hardware is deployed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eBlock all external access to the web-based management interface of the Totolink A3002MU router at the firewall level.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to isolate vulnerable network hardware from critical business infrastructure.\u003c/li\u003e\n\u003cli\u003eMonitor ingress traffic to the '/boafrm/formFilter' endpoint for excessive payload lengths or suspicious characters within the 'ip6addr' argument.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-14T01:29:02Z","date_published":"2026-09-14T01:28:44Z","id":"https://feed.craftedsignal.io/briefs/2026-09-totolink-buffer-overflow/","summary":"A critical buffer overflow vulnerability in the Totolink A3002MU router allows unauthenticated remote attackers to trigger memory corruption via the /boafrm/formFilter endpoint.","title":"Remote Buffer Overflow in Totolink A3002MU Router","url":"https://feed.craftedsignal.io/briefs/2026-09-totolink-buffer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - A3002MU (Hh-B20211125.1046)","version":"https://jsonfeed.org/version/1.1"}