Remote Buffer Overflow in the Totolink A3002MU Management Interface

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-90606?

CVE-2026-90606 is a vulnerability classified as Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') and Improper Restriction of Operations within the Bounds of a Memory Buffer, affecting A3002MU (affected versions: Hh-B20211125.1046). This vulnerability is rated Critical, with a CVSS score of 9.4. Public exploit code or evidence is available for this vulnerability, but that does not confirm exploitation in the wild.

Overview

Original source data

A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

Affected products and scope

  • Totolink A3002MU firmware Hh-B20211125.1046 is identified as affected.
  • The relevant component is the boa web server, specifically the formIpv6Setup function and /boafrm/formIpv6Setup endpoint.
  • No evidence confirms the status of other versions, parallel branches, or a specific fixed release. Versions not identified above remain unknown.

Technical details

Totolink A3002MU processes the attacker-controlled static_ipv6 parameter in the formIpv6Setup function of the boa web server, implemented in /bin/boa. Public analysis states that this value is copied into a fixed-size buffer without a reliable length check, so oversized input can overwrite adjacent memory. The relevant entry point is the HTTP administration interface POST /boafrm/formIpv6Setup; the available evidence indicates that the attacker must reach this interface remotely and have low-level access privileges. Public verification caused the Boa process or web service to stop responding, confirming a denial-of-service condition. The memory overwrite could enable broader confidentiality, integrity, or availability effects, but the public evidence does not confirm code execution or a specific privilege-escalation path.

Exploitability

The vulnerability is reachable over the network through the device's web administration interface. The CVE data states that exploitation requires low privileges, does not require user interaction, and has low complexity. The administration interface must be reachable for the malicious request to be processed. A PoC has been disclosed publicly; the public analysis shows that an overlong static_ipv6 value can make the web service stop responding. The evidence reviewed confirms public PoC availability, but does not establish active exploitation, a named campaign, or specific victims.

Technical impact

The flaw allows input to exceed the intended boundary of a fixed-size buffer and potentially overwrite memory used by the Boa process. The publicly demonstrated outcome is that the router's web service stops responding, removing web management access. If the overwritten memory can be controlled beyond a crash, the device's confidentiality, integrity, and availability could be affected, but the available evidence does not confirm code execution or complete device takeover. Realistic organisational effects include loss of administration, incident-response and recovery work, and possible equipment replacement; the effect on packet forwarding or other router functions is not established.

Business impact

  • The device may lose web administration if the Boa service hangs or stops responding, causing operational disruption and increasing recovery time.
  • Routers with administration interfaces exposed to untrusted networks may be targeted remotely when an attacker can obtain the required low-level privileges.
  • If the memory overwrite can be controlled beyond a service crash, the effect could extend to device confidentiality or integrity; the public PoC does not demonstrate this.
  • Because no confirmed fixed release is available, operators may need to replace affected equipment or accept residual risk while waiting for vendor guidance.

Remediation

  1. Replace the affected device or firmware with a vendor-supported alternative product or firmware, because no specific fixed release has been confirmed.
  2. Until replacement, restrict the administration interface to trusted management networks as a precaution. This is exposure-reduction guidance based on remote reachability, not a confirmed official mitigation.
  3. Do not treat another firmware release as safe unless Totolink directly confirms its status. The available record does not establish the affected scope of other branches or versions.
  4. Monitor Totolink support guidance for a confirmed fixed release or mitigation before returning the device to a network where the administration interface can be reached remotely.

Detection

  • Inventory Totolink A3002MU devices and verify their running firmware, especially Hh-B20211125.1046.
  • Determine whether each device's administration interface is reachable from untrusted networks, which is an important condition for remote exploitation.
  • If HTTP access logs or a reverse proxy are available, review requests to /boafrm/formIpv6Setup containing unusually long static_ipv6 values. This is precautionary review guidance, not a confirmed IOC.
  • Check for the administration interface or Boa web service becoming unresponsive after an unusual request, together with router restarts or loss of management access.
  • The available evidence does not provide a complete log pattern or IOC. The absence of a matching event does not prove that a device is safe.
Sources (10)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan