SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90606

CRITICAL · CVSS 9.9 EPSS 0.49% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A critical buffer overflow vulnerability exists in the Totolink A3002MU router, specifically within the formIpv6Setup function, which can be exploited remotely by manipulating the static_ipv6 argument. Successful exploitation could allow an attacker to execute arbitrary code on the device, potentially compromising the network's security. Organizations using this router model should prioritize immediate patching or mitigation measures to protect against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90606
Severity
CRITICAL
CVSS
9.9
EPSS
0.49%

Original NVD Description

A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.