CVE-2026-90608

A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.

  • Published Sep 14, 2026
  • CVSS 8.6 high
  • 0.9% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-90608 at the National Vulnerability Database