criticalOther

Totolink A3002MU boa formFilter Remote Buffer Overflow (CVE-2026-90605)

First seen Sep 14, 2026 · Updated Sep 14, 2026 · CVSS 9.9

iotrouterbuffer-overflowremote-code-executiontotolinkboa-serverpublic-exploit

A critical remote buffer overflow vulnerability has been identified in Totolink A3002MU routers running firmware Hh-B20211125.1046, affecting the formFilter function within the boa web server component. Public exploit code is available, significantly increasing the risk of widespread exploitation against internet-facing devices.

Technical Analysis

The vulnerability resides in the formFilter handler at /boafrm/formFilter within the boa embedded web server used by Totolink A3002MU devices. Improper bounds checking on the ip6addr parameter allows an attacker to trigger a buffer overflow, potentially leading to remote code execution or denial of service. The flaw is remotely exploitable without requiring physical access, and the CVSS score of 9.9 reflects low attack complexity and high impact on confidentiality, integrity, and availability. Public availability of exploit code substantially lowers the barrier for opportunistic attackers, including botnet operators seeking to conscript vulnerable routers. While this is a consumer/SMB networking device vulnerability rather than a direct compromise of AI agent infrastructure, organizations deploying edge AI agents, IoT-connected agent pipelines, or remote inference endpoints behind affected routers could face network-layer compromise, traffic interception, or lateral movement into environments where agent credentials and API keys are transmitted or stored.

Affected Systems

Totolink A3002MU router, firmware version Hh-B20211125.1046, boa web server component, formFilter function accessible via /boafrm/formFilter endpoint

Indicators of Compromise

  • Endpoint: /boafrm/formFilter
  • Parameter: ip6addr (malformed/oversized input)
  • Note: No specific hashes, IPs, or domains provided in source data; monitor vendor advisories and threat intel feeds for exploitation indicators

Remediation Steps

  1. 1

    Apply Firmware Update

    Check Totolink's official support channels for a patched firmware release addressing this vulnerability and apply it immediately once available.

  2. 2

    Restrict Remote Access

    Disable remote/WAN-facing administration interfaces on the router and restrict access to the boa web server to trusted internal networks only.

  3. 3

    Network Segmentation

    Isolate IoT and edge devices, including routers running boa, from segments hosting AI agent infrastructure, credential stores, or sensitive API endpoints.

  4. 4

    Monitor for Exploitation

    Deploy network intrusion detection signatures for anomalous traffic targeting /boafrm/formFilter and unusual ip6addr parameter values.

  5. 5

    Device Replacement Consideration

    If no patch is released, evaluate replacing affected end-of-life or unsupported Totolink devices with actively maintained hardware.

CVE / Advisory IDs

CVE-2026-90605

Industries Most Exposed

Consumer/Home NetworkingSmall and Medium BusinessTelecommunicationsCritical Infrastructure (edge networking)Managed Service Providers

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.