criticalZero-Day

Totolink A3002MU formWlAc Buffer Overflow (CVE-2026-93739)

First seen Sep 20, 2026 · Updated Sep 20, 2026 · CVSS 9.9

iotrouterbuffer-overflowrcetotolinkpublicly-disclosednetwork-device

A critical remotely exploitable buffer overflow vulnerability affects the Totolink A3002MU router firmware Hh-B20211125.1046, specifically in the formWlAc function handling the submit-url parameter. The exploit has been publicly disclosed, significantly increasing the likelihood of active exploitation attempts against exposed devices.

Technical Analysis

CVE-2026-93739 is a stack/heap-based buffer overflow in the formWlAc function within /boafrm/formWlAc on Totolink A3002MU devices running firmware Hh-B20211125.1046. The vulnerability arises from insufficient bounds checking on the submit-url argument, which an unauthenticated remote attacker can manipulate to overflow a buffer and potentially achieve arbitrary code execution or device crash. With a CVSS score of 9.9 and public exploit code available, this is a high-priority target for botnet operators and IoT malware campaigns similar to Mirai variants. Organizations that deploy AI agents or edge inference workloads on or behind vulnerable Totolink routers face indirect risk: a compromised router can enable network-level man-in-the-middle attacks, DNS hijacking, or traffic interception that exposes API keys, credentials, and agent-to-tool communications, undermining the confidentiality and integrity of agent pipelines.

Affected Systems

Totolink A3002MU router, firmware version Hh-B20211125.1046, specifically the /boafrm/formWlAc endpoint accessible via the device's web management interface

Indicators of Compromise

  • Endpoint targeted: /boafrm/formWlAc
  • Vulnerable parameter: submit-url
  • No confirmed hashes, IPs, or malware samples publicly attributed at time of disclosure

Remediation Steps

  1. 1

    Apply Firmware Update

    Check Totolink's official support site for a patched firmware release addressing CVE-2026-93739 and apply it immediately once available.

  2. 2

    Restrict Remote Management

    Disable remote/WAN-side access to the router's web administration interface; restrict management access to trusted LAN IPs only.

  3. 3

    Network Segmentation

    Isolate IoT and network infrastructure devices from segments hosting AI agent systems, credential stores, and sensitive data pipelines.

  4. 4

    Monitor for Exploitation

    Deploy IDS/IPS signatures for anomalous POST requests to /boafrm/formWlAc and monitor for unexpected reboots or configuration changes.

  5. 5

    Replace End-of-Life Devices

    If no patch is issued, consider replacing the affected device with a actively supported router model.

CVE / Advisory IDs

CVE-2026-93739

Industries Most Exposed

consumer electronicstelecommunicationssmall business/home office networkingcritical infrastructure (SOHO gateways)managed service providers

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.