A publicly disclosed buffer overflow in the Totolink A3002MU router's boa web server lets a remote, low-privileged attacker corrupt memory via the IPv6 setup handler, carrying a CVSS 3.1 score of 9.9 (Critical).
What Is It
The flaw sits in the formIpv6Setup function of /boafrm/formIpv6Setup, part of the boa component on Totolink A3002MU firmware Hh-B20211125.1046. Manipulating the static_ipv6 argument triggers a buffer overflow. The CNA (VulDB) classifies the weakness as CWE-119 (improper restriction of operations within the bounds of a memory buffer) and CWE-120 (classic buffer overflow); because NVD analysis is still pending, NVD has not yet assigned its own weakness mapping. The attack can be carried out remotely, and the exploit has been publicly disclosed and may be used.
Why It Matters
The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network-reachable, low attack complexity, no user interaction, and only low privileges required. The scope is Changed, with high confidentiality, integrity, and availability impact, producing a 9.9 Critical base score. The CVSS 4.0 assessment from the CNA rates it 8.6 (High) and sets exploit maturity to Proof-of-Concept, reflecting the public write-up. A reliably weaponized overflow in the router's web server would put an attacker on the device that fronts an entire network segment, though the available data does not establish that the published proof-of-concept achieves code execution rather than a crash.
There is no CISA KEV entry for this CVE, so active in-the-wild exploitation is not confirmed at this time. Public exploit details still lower the bar for opportunistic attacks.
What's Vulnerable
- Vendor: Totolink
- Product: A3002MU
- Affected version: Hh-B20211125.1046
- Component:
boa(web server), functionformIpv6Setup, endpoint/boafrm/formIpv6Setup - Parameter:
static_ipv6
CPE: cpe:2.3:a:totolink:a3002mu:*:*:*:*:*:*:*:*
Patch Status
The supplied record lists no patch, fixed version, or vendor advisory, and no CISA-mandated required action. The CVE record carries a vulnerability status of "Received," meaning NVD analysis is still pending and the currently published scoring and classification data originate from the CNA. Until Totolink publishes a fix, restricting access to the router's administrative web interface is the only leverage the available data supports.
Sources
- NVD, CVE-2026-90606: https://nvd.nist.gov/vuln/detail/CVE-2026-90606
- VulDB, CVE-2026-90606: https://vuldb.com/cve/CVE-2026-90606
- VulDB, Vulnerability 403188: https://vuldb.com/vuln/403188
- VulDB, CTI details: https://vuldb.com/vuln/403188/cti
- VulDB, Submission 914010: https://vuldb.com/submit/914010
- Researcher write-up (SunnyYANGyaya): https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A3002MU/bof-formIpv6Setup.md
- Totolink: https://www.totolink.net/