criticalOther

Totolink A3002MU formWlWds Remote Buffer Overflow

First seen Sep 21, 2026 · Updated Sep 21, 2026 · CVSS 10

iotrouterbuffer-overflowrcepublic-exploittotolinknetwork-device

A critical remote buffer overflow vulnerability affects the Totolink A3002MU router firmware Hh-B20211125.1046, specifically in the formWlWds function handling the submit-url parameter. A public exploit is available, allowing unauthenticated remote attackers to potentially achieve code execution or device compromise with no user interaction required.

Technical Analysis

The vulnerability resides in /boafrm/formWlWds, part of the Boa-based web management interface commonly found in Totolink router firmware. Improper bounds checking on the submit-url argument allows an attacker to trigger a stack-based buffer overflow, potentially leading to remote code execution on the device. Given the CVSS score of 10.0, exploitation likely requires no authentication and can be performed over the network, making internet-exposed or improperly segmented devices highly at risk. Public availability of exploit code significantly lowers the barrier to attack and increases the likelihood of mass scanning and exploitation campaigns, similar to prior Totolink CVEs weaponized by IoT botnets (e.g., Mirai variants). For organizations running AI agents or LLM-based automation on edge networks, a compromised router could serve as a pivot point to intercept or manipulate API traffic, exfiltrate credentials/API keys used by agent tooling, or enable man-in-the-middle attacks against RAG pipelines and agent-to-cloud communications, making this agent-relevant infrastructure risk.

Affected Systems

Totolink A3002MU routers running firmware version Hh-B20211125.1046; web management interface component /boafrm/formWlWds

Indicators of Compromise

  • N/A - no specific hashes, IPs, or domains provided; monitor for anomalous POST requests to /boafrm/formWlWds with oversized submit-url parameter values

Remediation Steps

  1. 1

    Apply Firmware Update

    Check Totolink's official support channels for a patched firmware release addressing this buffer overflow and update immediately.

  2. 2

    Restrict Remote Access

    Disable remote/WAN administration access to the router's web interface and restrict management access to trusted internal networks only.

  3. 3

    Network Segmentation

    Isolate IoT and network infrastructure devices from critical systems, including hosts running AI agent workloads, to limit lateral movement in case of compromise.

  4. 4

    Monitor and Detect

    Deploy network intrusion detection signatures for exploitation attempts against formWlWds and monitor for abnormal traffic patterns from router management interfaces.

  5. 5

    Replace End-of-Life Devices

    If no patch is available, consider replacing the affected device with actively supported hardware.

CVE / Advisory IDs

CVE-2026-93741

Industries Most Exposed

Consumer/Home NetworkingSmall BusinessTelecommunicationsCritical Infrastructure (via exposed edge devices)

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.