Totolink A3002MU formSchedule Buffer Overflow (CVE-2026-93738)
First seen Sep 20, 2026 · Updated Sep 20, 2026 · CVSS 9.9
A critical remotely exploitable buffer overflow vulnerability was identified in Totolink A3002MU routers running firmware Hh-B20211125.1046, affecting the formSchedule function via manipulation of the webpage parameter. A public exploit is available, significantly increasing the likelihood of active exploitation against exposed devices.
Technical Analysis
The vulnerability resides in the formSchedule handler within /boafrm/formSchedule on the Boa-based web management interface of Totolink A3002MU routers. Improper bounds checking on the webpage argument allows an unauthenticated remote attacker to trigger a stack-based buffer overflow, potentially leading to arbitrary code execution or denial of service on the embedded MIPS/ARM device. With a CVSS score of 9.9 and public exploit code circulating, mass scanning and automated exploitation attempts are expected, consistent with historical patterns for Totolink CVEs used in IoT botnets (e.g., Mirai variants). Organizations deploying AI agents or edge inference workloads on or behind vulnerable Totolink routers face indirect risk, as compromise of the router could enable network-level man-in-the-middle attacks, DNS hijacking, or credential interception affecting API keys and traffic used by agentic systems communicating through that network path.
Affected Systems
Totolink A3002MU router, firmware version Hh-B20211125.1046 and potentially earlier/related firmware branches using the same formSchedule implementation
Indicators of Compromise
- Endpoint: /boafrm/formSchedule
- Parameter: webpage (malformed/oversized value)
- No public hashes, IPs, or domains disclosed at this time
Remediation Steps
- 1
Apply Firmware Update
Check Totolink's official support portal for a patched firmware release addressing this vulnerability and apply it immediately.
- 2
Restrict Remote Access
Disable remote/WAN-facing management interfaces on the router and restrict administrative access to trusted LAN segments only.
- 3
Network Segmentation
Isolate IoT and embedded network devices, including routers, from segments hosting AI agent infrastructure, credential stores, or API gateways.
- 4
Monitor for Exploitation
Deploy IDS/IPS signatures for anomalous requests to /boafrm/formSchedule and monitor for unusual outbound traffic indicative of compromise.
- 5
Replace End-of-Life Devices
If no patch is available, consider replacing affected Totolink devices with actively supported hardware.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.