criticalZero-Day

Totolink A3002MU formIpv6Setup Buffer Overflow (CVE-2026-90606)

First seen Sep 14, 2026 · Updated Sep 14, 2026 · CVSS 9.9

buffer-overflowrouter-vulnerabilityiotremote-code-executionunauthenticatedpublic-exploittotolinkboa-webserver

A critical unauthenticated remote buffer overflow vulnerability has been identified in Totolink A3002MU routers running firmware Hh-B20211125.1046, affecting the formIpv6Setup function in the boa web server component. A public exploit is available, and the flaw can be triggered remotely via the static_ipv6 parameter, potentially allowing full device compromise.

Technical Analysis

The vulnerability resides in the formIpv6Setup function within /boafrm/formIpv6Setup, part of the boa embedded web server used in Totolink A3002MU router firmware. Improper bounds checking on the static_ipv6 parameter allows an attacker to trigger a stack-based buffer overflow, potentially leading to remote code execution or denial of service on the device. Given the CVSS score of 9.9, the vulnerability is likely exploitable without authentication and over the network, making mass scanning and exploitation feasible, especially since a public exploit already exists. Compromised routers of this type are commonly used in botnet campaigns (e.g., Mirai-style malware) for DDoS, traffic interception, or as pivot points into internal networks. While this is a consumer/SOHO router vulnerability with no direct AI agent software involved, organizations running AI agents or edge inference workloads behind such compromised network infrastructure could face traffic interception, credential exfiltration (including API keys used by agents), or lateral movement into agent-hosting environments if these devices sit on the same network perimeter.

Affected Systems

Totolink A3002MU router firmware version Hh-B20211125.1046, specifically the boa web server component and its formIpv6Setup handler

Indicators of Compromise

  • N/A - No specific hashes, IPs, or domains disclosed in source data; monitor for exploitation attempts targeting /boafrm/formIpv6Setup endpoint with malformed static_ipv6 parameter values

Remediation Steps

  1. 1

    Apply Firmware Update

    Check Totolink's official support channels for a patched firmware release addressing this buffer overflow and apply it immediately once available.

  2. 2

    Restrict Remote Management Access

    Disable remote/WAN-facing administrative access to the router's web interface and restrict management to trusted internal networks only.

  3. 3

    Network Segmentation

    Isolate IoT and consumer-grade networking devices from segments hosting sensitive infrastructure, including systems running AI agent frameworks or API credential stores.

  4. 4

    Monitor for Exploitation

    Deploy IDS/IPS signatures to detect anomalous requests to /boafrm/formIpv6Setup and monitor for unusual outbound traffic indicative of botnet recruitment.

  5. 5

    Device Replacement

    If no patch is issued by the vendor, consider replacing affected devices with hardware that receives active security support.

CVE / Advisory IDs

CVE-2026-90606

Industries Most Exposed

Consumer/Home NetworkingSmall BusinessTelecommunicationsCritical Infrastructure (SOHO edge devices)Managed Service Providers

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.