CVE-2026-93738

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

  • Published Sep 18, 2026
  • CVSS 8.6 high
  • 0.9% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-93738 at the National Vulnerability Database