CVE-2026-90604
A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
- Published Sep 14, 2026
- CVSS 2.0 low
- 0.3% chance of exploitation in the next 30 days (EPSS)