CVE-2026-105284
published 2026-10-05CVE-2026-105284: A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component…
PriorityP268critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
0.78%
54.6th percentile
A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| totolink | a3002mu | — | — |
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Totolink A3002MU 1.0.0-B20230403.1455 Authentication Check /bin/boa sub_40FCFC improper authorization
vuldb·2026-10-05
CVE-2026-105284 Totolink A3002MU 1.0.0-B20230403.1455 Authentication Check /bin/boa sub_40FCFC improper authorization
A vulnerability, which was classified as very critical, was found in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization.
The identification of this vulnerability is CVE-2026-105284. The attack may be launched remotely. Furthermore, there is an exploit available.
GHSA
A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455.
ghsa_unreviewed·2026-10-05
CVE-2026-105284 [CRITICAL] CWE-266 A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455.
A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-10-05
Published