A critical improper authorization flaw in the Authentication Check component of Totolink A3002MU firmware 1.0.0-B20230403.1455 can be exploited remotely without credentials, and a public exploit has been released.
What Is It
CVE-2026-105284 is an improper authorization vulnerability in the Totolink A3002MU. The flaw sits in the function sub_40FCFC of the /bin/boa binary, inside the device's Authentication Check component. According to the CNA (VulDB), manipulating this function can lead to improper authorization, and the attack can be launched remotely.
The weakness is classified as CWE-266 (Incorrect Privilege Assignment) and CWE-285 (Improper Authorization). NVD published the record on 2026-10-05 and its status is still "Received."
Why It Matters
VulDB rates this flaw at the top of the severity scale:
- CVSS 3.1: 10.0 CRITICAL (
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) - CVSS 4.0: 9.3 CRITICAL, exploit maturity marked as Proof-of-Concept
- CVSS 2.0: 10.0
The vector shows network-based attack, low complexity, and no required privileges or user interaction. Impact on confidentiality, integrity, and availability is high, and the scope is changed. The CNA says the exploit "has been made available to the public and could be used for attacks." One of the references is a public GitHub Gist.
This CVE has no CISA KEV entry. CISA has not confirmed active exploitation in the wild as of publication.
What's Vulnerable
- Vendor: Totolink
- Product: A3002MU
- Affected version: 1.0.0-B20230403.1455
- Component: Authentication Check (
/bin/boa, functionsub_40FCFC) - CPE:
cpe:2.3:a:totolink:a3002mu:*:*:*:*:*:*:*:*
The supplied data lists no other versions as affected or unaffected.
Patch Status
The supplied NVD record contains no vendor advisory, fixed firmware version, or patch reference. Because the device is not in KEV, there is no CISA-required action or due date. Owners of affected A3002MU devices should check Totolink's website for firmware updates and watch the VulDB entries for changes.