Cyber & AI intelligence
Wasteland.
Briefs indexed2769
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-93742 2026-09-19

Totolink A3002MU Command Injection — CVE-2026-93742

"A public proof-of-concept exists for a critical command injection flaw in the Totolink A3002MU router's WPS handler, allowing a remote low-privileged attacker to execute arbitrary commands."

A public proof-of-concept exists for a critical command injection flaw in the Totolink A3002MU router's WPS handler, allowing a remote low-privileged attacker to execute arbitrary commands.

What Is It

CVE-2026-93742 is a command injection vulnerability (CWE-74, CWE-77) in the formWsc function of the file /boafrm/formWsc on Totolink A3002MU firmware Hh-B20211125.1046. Manipulating the localPin argument causes command injection. The attack can be initiated remotely, and the exploit has been made available to the public.

The flaw carries a CVSS v3.1 base score of 9.9 (CRITICAL) with vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network-reachable, low attack complexity, low privileges required, no user interaction, and a changed scope. The CVSS v4.0 assessment scores it 8.6 (HIGH) and flags exploit maturity as PROOF_OF_CONCEPT.

Why It Matters

The combination of network attack vector, low attack complexity, and only low privileges required means the barrier to exploitation is minimal. Scope is rated CHANGED, meaning impact extends beyond the vulnerable component itself; the v4.0 vector confirms HIGH confidentiality, integrity, and availability impact both to the vulnerable system and to subsequent systems.

Publicly available exploit code shortens the window between disclosure and opportunistic attack. Note that CISA has not added this CVE to the Known Exploited Vulnerabilities catalog; there is no KEV entry in the supplied data, and therefore no confirmation of active in-the-wild exploitation and no KEV-mandated remediation deadline.

What's Vulnerable

Patch Status

No patch, fixed version, or vendor advisory is identified in the supplied NVD record. The CVE was published 2026-09-19 with a vulnerability status of Received, meaning NVD analysis is not yet complete. No required action or remediation guidance is specified in the source data. Operators should monitor the vendor site for firmware updates.

Sources