---
id: CVE-2026-90605
title: A weakness has been identified in Totolink A3002MU Hh-B20211125.1046
summary: >-
  A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This
  vulnerability affects the function formFilter of the file /boafrm/formFilter
  of the component boa. Executing a manipulation of the argument ip6addr can
  lead to bu…
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-120
vendor: Totolink
product: A3002MU
affected:
  - A3002MU Hh-B20211125.1046
published: '2026-09-14'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T14:17:22.863'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90605'
references:
  - url: >-
      https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A3002MU/bof-formFilter.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90605'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/914009'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403187'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403187/cti'
    label: cna@vuldb.com
  - url: 'https://www.totolink.net/'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-15T13:49:13.706523Z'
epss: 0.00854
epssPercentile: 0.56542
ingestedAt: '2026-09-14T15:23:07.468Z'
---

## Overview

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
