CVE-2026-93742

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

  • Published Sep 19, 2026
  • CVSS 8.6 high
  • 2.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-93742 at the National Vulnerability Database