A published proof-of-concept exploit targets a remotely reachable buffer overflow in the Totolink A3002MU router's boa web component, scoring CVSS 3.1 9.9 (Critical).
What Is It
CVE-2026-90608 is a buffer overflow in the formPortFw function of /boafrm/formPortFw, part of the boa web server component on the Totolink A3002MU router. Manipulating the service_type argument overflows the buffer. The attack can be initiated remotely, and the exploit has been published and may be used.
The issue is tracked under CWE-119 (improper restriction of operations within the bounds of a memory buffer) and CWE-120 (classic buffer overflow). It was disclosed by VulDB ([email protected]) and is currently in "Received" status at NVD, the CNA submission has been ingested but has not yet been analyzed or fully published, so no NVD publication date is established.
Why It Matters
The CVSS 3.1 base score is 9.9 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Network attack vector, low complexity, no user interaction, and only low privileges required; combined with a changed scope and high confidentiality, integrity, and availability impact.
VulDB's CVSS 4.0 assessment scores it 8.6 (HIGH) with exploit maturity rated PROOF_OF_CONCEPT, reflecting that working exploit details are publicly available. The legacy CVSS 2.0 score is 9.0.
CVE-2026-90608 does not appear in the CISA Known Exploited Vulnerabilities catalog based on the supplied data, so there is no confirmation of active in-the-wild exploitation and no KEV-mandated remediation deadline. Public PoC availability against an embedded consumer router web interface still narrows the window between disclosure and opportunistic abuse.
What's Vulnerable
- Vendor: Totolink
- Product: A3002MU
- Affected version: Hh-B20211125.1046
- Affected component:
boa(web server) - Affected element: function
formPortFwin/boafrm/formPortFw - Vulnerable parameter:
service_type - CPE:
cpe:2.3:a:totolink:a3002mu:*:*:*:*:*:*:*:*
Patch Status
No patch, fixed version, or vendor advisory is identified in the supplied NVD record. The only vendor reference provided is the Totolink homepage. There is no CISA KEV required action associated with this CVE in the supplied data. Operators of affected devices should monitor Totolink for firmware updates and restrict network exposure of the device management interface.
Sources
- NVD, CVE-2026-90608: https://nvd.nist.gov/vuln/detail/CVE-2026-90608
- VulDB Entry 403190: https://vuldb.com/vuln/403190
- VulDB Threat Intelligence (403190): https://vuldb.com/vuln/403190/cti
- VulDB Submission 914016: https://vuldb.com/submit/914016
- Public PoC writeup,
bof-formPortFw.md: https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A3002MU/bof-formPortFw.md - Totolink vendor site: https://www.totolink.net/