CVE-2026-93739
9.9 CRITICALpublic exploit availablePublished 2026-09-18 · Updated 2026-09-23
AI risk analysis
- Summary
- The vulnerability in Totolink A3002MU Hh-B20211125.1046 allows for buffer overflow via manipulation of the submit-url argument, leading to potential remote code execution.
- Exploitability
- Exploitation is relatively straightforward from a remote location, requiring only control over the submit-url argument.
- Blast radius
- If exploited, this vulnerability could result in complete control of the device, potentially leading to data theft, service disruption, or further network compromise.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to the fixed version 1.0.1 or later.
buffer-overflowremote-code-executionwebfirmware
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-119, CWE-120
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-93740PoC
- HIGHCVE-2026-18898PoC
- CRITICALCVE-2026-94100
- CRITICALCVE-2026-94089PoC
- CRITICALCVE-2026-93738PoC
- CRITICALCVE-2026-93741PoC
- CRITICALCVE-2026-94101
- CRITICALCVE-2026-101074PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.