CVE-2026-93742Critical· 9.9▾ MidnightA weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be init…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
1.9%
Last analysed / modified upstream
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-93741Critical· 10.0A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046
CVE-2026-93739Critical· 9.9A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046
CVE-2026-93740Critical· 10.0A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046
CVE-2026-93738Critical· 9.9A vulnerability was found in Totolink A3002MU Hh-B20211125.1046
CVE-2026-91853High· 7.4A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224
CVE-2026-90604Low· 3.5A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046