SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90604

LOW · CVSS 3.5 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A cross-site scripting vulnerability exists in the Anchor Tag Handler of the Totolink A3002MU Hh-B20211125.1046, allowing remote attackers to manipulate content and potentially execute malicious scripts in the context of a user's session. While the severity is rated low, organizations using this device should prioritize patching or implementing mitigations to prevent potential exploitation, especially in environments where sensitive data is handled.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90604
Severity
LOW
CVSS
3.5
EPSS
0.20%

Original NVD Description

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.