<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>A3002MU (Hh-B20211125.1046) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/a3002mu-hh-b20211125.1046/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 14 Sep 2026 01:28:44 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/a3002mu-hh-b20211125.1046/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Buffer Overflow in Totolink A3002MU Router</title><link>https://feed.craftedsignal.io/briefs/2026-09-totolink-buffer-overflow/</link><pubDate>Mon, 14 Sep 2026 01:28:44 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-totolink-buffer-overflow/</guid><description>A critical buffer overflow vulnerability in the Totolink A3002MU router allows unauthenticated remote attackers to trigger memory corruption via the /boafrm/formFilter endpoint.</description><content:encoded><![CDATA[<p>A critical buffer overflow vulnerability (CVE-2026-90605) has been identified in the Totolink A3002MU router running firmware version Hh-B20211125.1046. The flaw exists within the 'formFilter' function of the 'boa' web server component. An unauthenticated remote attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the '/boafrm/formFilter' URI, specifically by manipulating the 'ip6addr' argument. Successful exploitation of this buffer overflow may result in arbitrary code execution or a denial of service condition. Given that exploit code for this vulnerability is publicly available, organizations using the affected router models face an immediate risk of compromise. Defenders should prioritize restricting access to the management interface and monitoring for anomalous HTTP traffic targeting the vulnerable endpoint.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-90605 grants an attacker the ability to achieve remote code execution on the affected network device. This allows for complete compromise of the router, potentially enabling traffic interception, man-in-the-middle attacks, or persistent access to the internal network. The vulnerability poses a significant risk to consumer and small-office environments where this hardware is deployed.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Block all external access to the web-based management interface of the Totolink A3002MU router at the firewall level.</li>
<li>Implement network segmentation to isolate vulnerable network hardware from critical business infrastructure.</li>
<li>Monitor ingress traffic to the '/boafrm/formFilter' endpoint for excessive payload lengths or suspicious characters within the 'ip6addr' argument.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>