Totolink A3002MU formWlAc Buffer Overflow (CVE-2026-93739)
First seen Sep 20, 2026 · Updated Sep 20, 2026 · CVSS 9.9
A critical remotely exploitable buffer overflow vulnerability affects the Totolink A3002MU router firmware Hh-B20211125.1046, specifically in the formWlAc function handling the submit-url parameter. The exploit has been publicly disclosed, significantly increasing the likelihood of active exploitation attempts against exposed devices.
Technical Analysis
CVE-2026-93739 is a stack/heap-based buffer overflow in the formWlAc function within /boafrm/formWlAc on Totolink A3002MU devices running firmware Hh-B20211125.1046. The vulnerability arises from insufficient bounds checking on the submit-url argument, which an unauthenticated remote attacker can manipulate to overflow a buffer and potentially achieve arbitrary code execution or device crash. With a CVSS score of 9.9 and public exploit code available, this is a high-priority target for botnet operators and IoT malware campaigns similar to Mirai variants. Organizations that deploy AI agents or edge inference workloads on or behind vulnerable Totolink routers face indirect risk: a compromised router can enable network-level man-in-the-middle attacks, DNS hijacking, or traffic interception that exposes API keys, credentials, and agent-to-tool communications, undermining the confidentiality and integrity of agent pipelines.
Affected Systems
Totolink A3002MU router, firmware version Hh-B20211125.1046, specifically the /boafrm/formWlAc endpoint accessible via the device's web management interface
Indicators of Compromise
- Endpoint targeted: /boafrm/formWlAc
- Vulnerable parameter: submit-url
- No confirmed hashes, IPs, or malware samples publicly attributed at time of disclosure
Remediation Steps
- 1
Apply Firmware Update
Check Totolink's official support site for a patched firmware release addressing CVE-2026-93739 and apply it immediately once available.
- 2
Restrict Remote Management
Disable remote/WAN-side access to the router's web administration interface; restrict management access to trusted LAN IPs only.
- 3
Network Segmentation
Isolate IoT and network infrastructure devices from segments hosting AI agent systems, credential stores, and sensitive data pipelines.
- 4
Monitor for Exploitation
Deploy IDS/IPS signatures for anomalous POST requests to /boafrm/formWlAc and monitor for unexpected reboots or configuration changes.
- 5
Replace End-of-Life Devices
If no patch is issued, consider replacing the affected device with a actively supported router model.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.