SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90607

CRITICAL · CVSS 9.9 EPSS 0.47% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A critical buffer overflow vulnerability exists in the Totolink A3002MU router, specifically within the formNewSchedule function of the boa component, which can be exploited remotely through manipulation of the submit-url argument. Successful exploitation could allow attackers to execute arbitrary code, potentially compromising the device and the network it is connected to. Organizations using this router model should prioritize immediate patching or mitigation efforts to safeguard against potential attacks, as the exploit is now publicly available.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90607
Severity
CRITICAL
CVSS
9.9
EPSS
0.47%

Original NVD Description

A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.