---
id: CVE-2026-26731
title: >-
  TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based
  buffer overflow via the routernamer`parameter in the formDnsv6 function.
summary: >-
  TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based
  buffer overflow via the routernamer`parameter in the formDnsv6 function.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
  - CWE-121
vendor: totolink
product: a3002ru_firmware
affected:
  - a3002ru_firmware = 2.1.1-b20211108.1455
published: '2026-02-17'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T20:17:23.643'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-26731'
references:
  - url: >-
      https://github.com/0xmania/cve/tree/main/TOTOLINK-A3002RU-boa-formDnsv6-StackOverflow
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-03-16T15:08:44.465963Z'
scores:
  nvd: 8.8
  adp: 8
epss: 0.01328
epssPercentile: 0.6982
ingestedAt: '2026-09-21T19:51:58.868Z'
---

## Overview

TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.

## Affected

- `a3002ru_firmware = 2.1.1-b20211108.1455`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
