Totolink A3002MU formPortFw Buffer Overflow (CVE-2026-90608)
First seen Sep 14, 2026 · Updated Sep 14, 2026 · CVSS 9.9
A critical remotely exploitable buffer overflow has been identified in the Totolink A3002MU router firmware (Hh-B20211125.1046), affecting the formPortFw function within the boa web server component. A public exploit is available, allowing unauthenticated attackers to potentially achieve remote code execution or device compromise via the service_type parameter.
Technical Analysis
The vulnerability resides in the formPortFw handler within /boafrm/formPortFw, part of the boa embedded web server used for router administration on Totolink A3002MU devices. Insufficient bounds checking on the service_type argument allows an attacker to trigger a stack or heap-based buffer overflow, potentially leading to remote code execution with elevated privileges on the device's underlying Linux-based firmware. The attack is remotely exploitable, does not appear to require prior authentication in many known boa-based Totolink flaws, and a working exploit has already been published, increasing the likelihood of mass scanning and exploitation. Given the CVSS score of 9.9, successful exploitation could grant full control over the router, enabling traffic interception, lateral network pivoting, or inclusion in botnets. Organizations running AI agents or edge inference workloads behind or on compromised SOHO/branch routers face risk of network-level man-in-the-middle interception of agent API traffic, credential/API key exfiltration, and disruption of RAG pipeline connectivity if attackers pivot from the compromised router into internal agent infrastructure.
Affected Systems
Totolink A3002MU routers running firmware version Hh-B20211125.1046; devices with the boa web server component and exposed formPortFw functionality accessible via LAN or WAN administrative interfaces.
Indicators of Compromise
- N/A - IoT firmware vulnerability, no specific hashes/domains published; monitor for anomalous POST requests to /boafrm/formPortFw with malformed service_type parameter values
Remediation Steps
- 1
Apply Firmware Update
Check Totolink's official support channels for a patched firmware release addressing CVE-2026-90608 and apply immediately once available.
- 2
Restrict Administrative Access
Disable remote/WAN-facing administration interfaces and restrict access to the router's web management panel to trusted LAN IPs only.
- 3
Network Segmentation
Isolate IoT and network infrastructure devices from segments hosting AI agent, RAG, or LLM tool-use infrastructure to limit lateral movement risk.
- 4
Monitor and Detect
Deploy IDS/IPS signatures to detect exploitation attempts against /boafrm/formPortFw and monitor for unusual outbound traffic from affected devices.
- 5
Replace End-of-Life Devices
If no patch is issued, consider replacing affected Totolink devices with actively supported hardware, as SOHO routers are frequently abandoned post-vulnerability disclosure.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.