Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-90608 2026-09-13

Totolink A3002MU Buffer Overflow in formPortFw (CVE-2026-90608)

"A published proof-of-concept exploit targets a remotely reachable buffer overflow in the Totolink A3002MU router's boa web component, scoring CVSS 3.1 9.9 (Critical)."

A published proof-of-concept exploit targets a remotely reachable buffer overflow in the Totolink A3002MU router's boa web component, scoring CVSS 3.1 9.9 (Critical).

What Is It

CVE-2026-90608 is a buffer overflow in the formPortFw function of /boafrm/formPortFw, part of the boa web server component on the Totolink A3002MU router. Manipulating the service_type argument overflows the buffer. The attack can be initiated remotely, and the exploit has been published and may be used.

The issue is tracked under CWE-119 (improper restriction of operations within the bounds of a memory buffer) and CWE-120 (classic buffer overflow). It was disclosed by VulDB ([email protected]) and is currently in "Received" status at NVD, the CNA submission has been ingested but has not yet been analyzed or fully published, so no NVD publication date is established.

Why It Matters

The CVSS 3.1 base score is 9.9 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Network attack vector, low complexity, no user interaction, and only low privileges required; combined with a changed scope and high confidentiality, integrity, and availability impact.

VulDB's CVSS 4.0 assessment scores it 8.6 (HIGH) with exploit maturity rated PROOF_OF_CONCEPT, reflecting that working exploit details are publicly available. The legacy CVSS 2.0 score is 9.0.

CVE-2026-90608 does not appear in the CISA Known Exploited Vulnerabilities catalog based on the supplied data, so there is no confirmation of active in-the-wild exploitation and no KEV-mandated remediation deadline. Public PoC availability against an embedded consumer router web interface still narrows the window between disclosure and opportunistic abuse.

What's Vulnerable

Patch Status

No patch, fixed version, or vendor advisory is identified in the supplied NVD record. The only vendor reference provided is the Totolink homepage. There is no CISA KEV required action associated with this CVE in the supplied data. Operators of affected devices should monitor Totolink for firmware updates and restrict network exposure of the device management interface.

Sources