GHSA-v9cq-jhv2-723gHighCVSS 9.9
A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function...
🔗 CVE IDs covered (1)
📋 Description
A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-90608
- https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A3002MU/bof-formPortFw.md
- https://vuldb.com/cve/CVE-2026-90608
- https://vuldb.com/submit/914016
- https://vuldb.com/vuln/403190
- https://vuldb.com/vuln/403190/cti
- https://www.totolink.net
- https://github.com/advisories/GHSA-v9cq-jhv2-723g