OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-105285

CRITICAL · CVSS 10 EPSS 1.10% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A critical stack-based buffer overflow vulnerability exists in the QoS Rule Handler of Totolink A3002MU firmware version 1.0.0-B20230403.1455, allowing remote attackers to manipulate specific arguments and execute arbitrary code. Organizations using this device should prioritize immediate patching or mitigation measures, as the exploit is publicly disclosed and can be readily exploited.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105285
Severity
CRITICAL
CVSS
10
EPSS
1.10%

Original NVD Description

A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file /boafrm/formIpQoS of the component QoS Rule Handler. The manipulation of the argument addQos/comment/entry_name leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.