Totolink A3002MU formWsc Command Injection (CVE-2026-93742)
First seen Sep 21, 2026 · Updated Sep 21, 2026 · CVSS 9.9
A critical unauthenticated command injection vulnerability affects the Totolink A3002MU router firmware Hh-B20211125.1046, exploitable via the localPin parameter in the formWsc function. Public exploit code exists, enabling remote attackers to execute arbitrary commands on the device without authentication, likely leading to full device compromise.
Technical Analysis
The vulnerability resides in /boafrm/formWsc, where the localPin parameter is passed unsanitized into a system-level command execution context, resulting in OS command injection. Exploitation requires no authentication and can be triggered remotely over the network, typically via crafted HTTP requests to the router's web management interface. Given the CVSS score of 9.9, successful exploitation grants attackers root-level control over the device, enabling firmware modification, traffic interception, or use as a foothold for lateral movement or botnet recruitment. Organizations deploying edge or IoT-connected AI agent infrastructure (e.g., agents relying on local network gateways, VPN routers, or edge devices for connectivity) could see agent communications intercepted, redirected, or disrupted if these compromised routers sit on the network path between agents and their cloud APIs.
Affected Systems
Totolink A3002MU router running firmware version Hh-B20211125.1046 and potentially other firmware versions sharing the same formWsc implementation
Indicators of Compromise
- Endpoint: /boafrm/formWsc
- Parameter: localPin (injection vector)
- No specific hashes, IPs, or domains published at this time
Remediation Steps
- 1
Apply Firmware Update
Check Totolink's official support channels for a patched firmware release addressing this command injection flaw and apply it immediately.
- 2
Restrict Management Interface Access
Disable remote/WAN access to the router's web management interface and restrict access to trusted internal networks only.
- 3
Network Segmentation
Isolate IoT and router management interfaces from critical infrastructure and AI agent networks to limit blast radius if compromised.
- 4
Monitor for Exploitation Attempts
Deploy IDS/IPS signatures targeting requests to /boafrm/formWsc with anomalous localPin payloads containing shell metacharacters.
- 5
Device Replacement Consideration
If no patch is available, consider replacing affected devices, especially in environments supporting sensitive or automated agent workloads.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.