A publicly disclosed buffer overflow in the Totolink A3002MU router's formWlAc handler could allow a remote, low-privileged attacker to compromise the device, and is rated CVSS 9.9 CRITICAL.
What Is It
CVE-2026-93739 is a buffer overflow (CWE-119 / CWE-120) reported in Totolink A3002MU firmware version Hh-B20211125.1046. The flaw is described as sitting in the formWlAc function of the file /boafrm/formWlAc. Manipulating the submit-url argument is reported to trigger the overflow. The attack is described as remotely exploitable, and per the NVD record, the exploit has been publicly disclosed and may be utilized.
Why It Matters
The CVSS 3.1 base score is 9.9 (CRITICAL), vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network attack vector, low attack complexity, only low privileges required, no user interaction, and a changed scope with high confidentiality, integrity, and availability impact. The CVSS 4.0 assessment scores 8.6 (HIGH) and marks exploit maturity as PROOF-OF-CONCEPT, which indicates that exploit material is reported to be publicly available. Note that these scores reflect the submitter's and NVD's assessment rather than independently verified exploitation outcomes; a proof-of-concept does not necessarily demonstrate reliable, full device takeover in the field.
There is no CISA KEV entry for this CVE in the supplied data, so active in-the-wild exploitation is not confirmed. That distinction may matter less than it normally would: a public PoC against an edge networking device with a scope-changing overflow fits a profile that attackers have historically picked up quickly, though that is a pattern-based expectation, not an observation about this CVE.
What's Vulnerable
- Vendor: Totolink
- Product: A3002MU
- Affected version: Hh-B20211125.1046
- CPE (as recorded):
cpe:2.3:a:totolink:a3002mu:*:*:*:*:*:*:*:* - Affected component:
formWlAcfunction in/boafrm/formWlAc
The CPE string above should be read with caution. Its part field is a (application), which is inconsistent with the rest of the record: the A3002MU is a router, and the affected version Hh-B20211125.1046 is a firmware build. Entries of this kind are normally expressed as a hardware CPE (h) for the device or an OS CPE (o) against a *_firmware product. The record is still in Received status, so this is plausibly an artifact of the initial submission that NVD analysis has not yet corrected. Do not rely on this CPE for automated asset matching without confirming against the vendor model and firmware build directly.
Only the single firmware build above is listed as affected in the supplied record. No other versions or models are enumerated, though absence from the record is not evidence that other builds are unaffected.
Patch Status
The supplied source material contains no vendor advisory, no fixed firmware version, and no CISA KEV required-action or due-date entry. The CVE record was published 2026-09-18 with a vulnerability status of Received, meaning NVD analysis is not yet complete and the details above may change. Until Totolink publishes updated firmware, operators should treat exposed A3002MU management interfaces as untrusted and restrict network reachability to them.
Sources
- NVD, CVE-2026-93739: https://nvd.nist.gov/vuln/detail/CVE-2026-93739
- VulDB, CVE-2026-93739: https://vuldb.com/cve/CVE-2026-93739
- VulDB, Vulnerability 407549: https://vuldb.com/vuln/407549
- VulDB, CTI details: https://vuldb.com/vuln/407549/cti
- VulDB, Submission 914018: https://vuldb.com/submit/914018
- Public write-up (SunnyYANGyaya),
bof-formWlAc.md: https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A3002MU/bof-formWlAc.md - Totolink vendor site: https://www.totolink.net/