CVE-2026-90605

CVE & Vulnerabilities · September 16, 2026

CVE & Vulnerabilities·nvd.nist.gov

CVE-2026-90605 affects the Totolink A3002MU router running firmware Hh-B20211125.1046, where the formFilter function in the device's boa web component fails to properly validate the ip6addr parameter. Sending a crafted value for that argument can trigger a buffer overflow, and because the flaw is reachable over the network, no physical access is required to attempt it. Proof-of-concept exploit code is already circulating publicly, so unpatched devices face a real risk of remote attack.

// source: nvd.nist.gov ↗

Back to Blog