CVE-2026-26731High· 8.8▾ MidnightPoC availableTOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 48.4 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
8 → 8.8
TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.
a3002ru_firmware = 2.1.1-b20211108.1455Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-61674Critical· 9.2Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows
CVE-2026-59181Medium· 6.1OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation
CVE-2026-63387High· 7.0Libevent is an event notification library
CVE-2026-93742Critical· 9.9A weakness has been identified in Totolink A3002MU Hh-B20211125.1046
CVE-2026-93740Critical· 10.0A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046
CVE-2026-91853High· 7.4A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224