Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-90605 2026-09-13

CVE-2026-90605: Totolink A3002MU Buffer Overflow with Public Exploit

"A remotely reachable buffer overflow in the `formFilter` handler of the Totolink A3002MU router's boa web server carries a CVSS 3.1 score of 9.9 and already has a publicly available exploit."

A remotely reachable buffer overflow in the formFilter handler of the Totolink A3002MU router's boa web server carries a CVSS 3.1 score of 9.9 and already has a publicly available exploit.

What Is It

The vulnerability sits in the function formFilter of the file /boafrm/formFilter, part of the boa component on the Totolink A3002MU router. An attacker who manipulates the ip6addr argument can trigger a buffer overflow. The CNA (VulDB) classifies the weakness as CWE-119 (improper restriction of operations within the bounds of a memory buffer) and CWE-120 (classic buffer overflow); because the NVD record has not yet been analyzed, NVD has not independently assigned a CWE.

The attack can be executed remotely. Per the CVE description as published by the CNA, the exploit has been made available to the public and could be used for attacks; the CVSS 4.0 metrics from the CNA mark exploit maturity as PROOF_OF_CONCEPT.

Why It Matters

All published severity scores for this CVE come from the CNA rather than from NVD analysts. The CNA's CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, base score 9.9, CRITICAL. Network-reachable, low attack complexity, no user interaction, and only low privileges required. The scope is CHANGED, meaning impact extends past the vulnerable component itself, with high confidentiality, integrity, and availability impact on both the vulnerable component and downstream. The CNA also assigned a CVSS 4.0 score of 8.6 (HIGH) and a CVSS 2.0 score of 9.0. These figures may be revised once NVD completes its own analysis.

Public exploit code plus a low privilege bar on a consumer/SMB router web interface is the combination that drives opportunistic scanning against edge devices.

What's Vulnerable

Per the CNA-supplied data (no NVD-validated configuration exists yet):

Patch Status

The NVD record for CVE-2026-90605 currently carries a vulnStatus of Received, meaning it has not yet completed NVD analysis and reflects only what the CNA submitted. Neither the NVD entry nor the VulDB entries list a vendor advisory or a fixed firmware version; the only vendor reference is a link to the Totolink site, which as of publication carries no advisory for this issue.

CVE-2026-90605 is not listed in CISA's Known Exploited Vulnerabilities catalog, so there is no KEV-confirmed active exploitation and no federal remediation deadline attached to it at this time. Treat exposure of the device's web interface to untrusted networks as the primary risk factor pending vendor guidance.

Sources