← back
CVE-2026-6194

Totolink A3002MU HTTP Request formWlanSetup sub_410188 stack-based overflow

CVSS 8.7 HIGHEPSS 0.5%CWE-119CWE-121
Vexday Risk Score
41Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 8.7EPSS 0.5%KEV nãoPoC públicaNuclei Metasploit Patch
Lifecycle
13 Apr 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_410188 of the file /boafrm/formWlanSetup of the component HTTP Request Handler. This manipulation of the argument wan-url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Affected products
Totolink · A3002MU
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →