CVE-2026-6194
HIGHTotolink A3002MU HTTP Request formWlanSetup sub_410188 stack-based overflow
Title source: cnaDescription
A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_410188 of the file /boafrm/formWlanSetup of the component HTTP Request Handler. This manipulation of the argument wan-url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Scores
CVSS v3
8.8
EPSS
0.0009
EPSS Percentile
24.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-119
CWE-121
Status
published
Products (1)
Totolink/A3002MU
B20211125.1046
Published
Apr 13, 2026
Tracked Since
Apr 13, 2026