criticalZero-Day

Totolink A3002MU formNewSchedule Buffer Overflow

First seen Sep 14, 2026 · Updated Sep 14, 2026 · CVSS 9.9

iotrouterbuffer-overflowremote-code-executiontotolinkpublic-exploit

A critical remote buffer overflow vulnerability affects the Totolink A3002MU router firmware Hh-B20211125.1046, specifically in the formNewSchedule function of the boa web server component. The flaw is exploitable remotely without authentication via the submit-url parameter, and public exploit code is already available, making active exploitation highly likely.

Technical Analysis

The vulnerability (CVE-2026-90607, CVSS 9.9) resides in the formNewSchedule handler within /boafrm/formNewSchedule of the boa embedded web server used by Totolink A3002MU routers. Improper bounds checking on the submit-url argument allows an attacker to trigger a stack-based buffer overflow, potentially leading to remote code execution on the device. Since the exploit is public and the attack requires no authentication, mass scanning and automated exploitation via botnets (e.g., Mirai-style) is probable. Organizations deploying edge AI agents or IoT gateways behind vulnerable Totolink routers could see network-level compromise, enabling traffic interception, man-in-the-middle attacks against API calls, or lateral movement toward hosts running agent frameworks and RAG pipelines that rely on these network devices for connectivity.

Affected Systems

Totolink A3002MU routers running firmware version Hh-B20211125.1046 and the boa web server component embedded in this firmware.

Indicators of Compromise

  • N/A - no specific hashes, IPs, or domains published; monitor for anomalous HTTP POST requests to /boafrm/formNewSchedule with oversized submit-url parameters

Remediation Steps

  1. 1

    Apply Firmware Update

    Check Totolink's official support channels for a patched firmware release addressing this vulnerability and apply it immediately.

  2. 2

    Restrict Remote Management

    Disable remote/WAN-facing administrative access to the router's web interface if not strictly required.

  3. 3

    Network Segmentation

    Isolate vulnerable IoT/router devices from critical infrastructure and AI agent hosting environments using VLANs or firewall rules.

  4. 4

    Monitor for Exploitation Attempts

    Deploy IDS/IPS signatures to detect exploitation attempts targeting the formNewSchedule endpoint and abnormal submit-url payload lengths.

  5. 5

    Replace End-of-Life Devices

    If the vendor does not release a patch, consider replacing affected devices with actively supported hardware.

CVE / Advisory IDs

CVE-2026-90607

Industries Most Exposed

consumer electronicstelecommunicationscritical infrastructuresmall business networkingIoT

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.