CVE-2026-93740
10 CRITICALpublic exploit availablePublished 2026-09-18 · Updated 2026-09-21
AI risk analysis
- Summary
- The vulnerability in Totolink A3002MU Hh-B20211125.1046 allows for remote buffer overflow via manipulation of the submit-url argument, leading to potential remote code execution.
- Exploitability
- Exploitation is relatively straightforward given the publicly available exploit, and requires only the ability to manipulate the submit-url argument.
- Blast radius
- If exploited, this vulnerability could lead to complete control of the affected device, potentially allowing attackers to execute arbitrary code and gain full access to the network.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to the fixed version 20211125.1046 or later.
buffer-overflowremote-code-executionwebfirmware
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-119, CWE-120
Public exploit & PoC references
All references
- https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A3002MU/bof-formWlEncrypt.md
- https://vuldb.com/cve/CVE-2026-93740
- https://vuldb.com/submit/914019
- https://vuldb.com/vuln/407550
- https://vuldb.com/vuln/407550/cti
- https://www.totolink.net/
- https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A3002MU/bof-formWlEncrypt.md
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-93739PoC
- HIGHCVE-2026-18898PoC
- CRITICALCVE-2026-94100
- CRITICALCVE-2026-94089PoC
- CRITICALCVE-2026-93738PoC
- CRITICALCVE-2026-93741PoC
- CRITICALCVE-2026-94101
- CRITICALCVE-2026-101074PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.