CVE-2026-93740

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

  • Published Sep 18, 2026
  • CVSS 9.3 critical
  • 0.9% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-93740 at the National Vulnerability Database