Totolink A3002Mu vulnerabilities
14 known vulnerabilities affecting totolink/a3002mu.
Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH1MEDIUM1LOW1
Vulnerabilities
Page 1 of 1
CVE-2026-105285P2CRITICALCVSS 10.0v1.0.0-B20230403.14552026-10-05
CVE-2026-105285 [CRITICAL] CWE-119 CVE-2026-105285: A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an
A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file /boafrm/formIpQoS of the component QoS Rule Handler. The manipulation of the argument addQos/comment/entry_name leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been
nvd
CVE-2026-93742P2CRITICALCVSS 9.9vHh-B20211125.10462026-09-19
CVE-2026-93742 [CRITICAL] CWE-74 CVE-2026-93742: A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
nvd
CVE-2026-93738P2CRITICALCVSS 9.9vHh-B20211125.10462026-09-18
CVE-2026-93738 [CRITICAL] CWE-119 CVE-2026-93738: A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSched
A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
nvd
CVE-2026-105284P2CRITICALCVSS 10.0v1.0.0-B20230403.14552026-10-05
CVE-2026-105284 [CRITICAL] CWE-266 CVE-2026-105284: A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the
A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and could be used
nvd
CVE-2026-90606P2CRITICALCVSS 9.9vHh-B20211125.10462026-09-14
CVE-2026-90606 [CRITICAL] CWE-119 CVE-2026-90606: A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects
A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and
nvd
CVE-2026-93740P2CRITICALCVSS 10.0vHh-B20211125.10462026-09-18
CVE-2026-93740 [CRITICAL] CWE-119 CVE-2026-93740: A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formW
A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
nvd
CVE-2026-6194P2HIGHCVSS 8.8vB20211125.10462026-04-13
CVE-2026-6194 [HIGH] CWE-119 CVE-2026-6194: A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is
A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_410188 of the file /boafrm/formWlanSetup of the component HTTP Request Handler. This manipulation of the argument wan-url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made availa
nvd
CVE-2026-90607P2CRITICALCVSS 9.9vHh-B20211125.10462026-09-14
CVE-2026-90607 [CRITICAL] CWE-119 CVE-2026-90607: A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNew
A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.
nvd
CVE-2026-90608P2CRITICALCVSS 9.9vHh-B20211125.10462026-09-14
CVE-2026-90608 [CRITICAL] CWE-119 CVE-2026-90608: A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function fo
A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.
nvd
CVE-2026-93739P2CRITICALCVSS 9.9vHh-B20211125.10462026-09-18
CVE-2026-93739 [CRITICAL] CWE-119 CVE-2026-93739: A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function form
A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
nvd
CVE-2026-90605P2CRITICALCVSS 9.9vHh-B20211125.10462026-09-14
CVE-2026-90605 [CRITICAL] CWE-119 CVE-2026-90605: A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could
nvd
CVE-2026-93741P2CRITICALCVSS 10.0vHh-B20211125.10462026-09-19
CVE-2026-93741 [CRITICAL] CWE-119 CVE-2026-93741: A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerab
A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for atta
nvd
CVE-2026-105286P3MEDIUMCVSS 6.3v1.0.0-B20230403.14552026-10-05
CVE-2026-105286 [MEDIUM] CWE-22 CVE-2026-105286: A vulnerability was detected in Totolink A3002MU 1.0.0-B20230403.1455. This impacts the function sub
A vulnerability was detected in Totolink A3002MU 1.0.0-B20230403.1455. This impacts the function sub_44B250 of the file /boafrm/formUploadFile of the component File Upload Handler. The manipulation of the argument filename results in path traversal. The attack can be executed remotely. The exploit is now public and may be used.
nvd
CVE-2026-90604P4LOWCVSS 3.5vHh-B20211125.10462026-09-14
CVE-2026-90604 [LOW] CWE-79 CVE-2026-90604: A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown p
A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
nvd