OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-93739

CRITICAL · CVSS 9.9 EPSS 0.85% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A critical buffer overflow vulnerability exists in the Totolink A3002MU router, specifically affecting the formWlAc function within the /boafrm/formWlAc file. This flaw can be exploited remotely by manipulating the submit-url argument, potentially allowing attackers to execute arbitrary code. Organizations using this router model should prioritize immediate mitigation efforts to prevent exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-93739
Severity
CRITICAL
CVSS
9.9
EPSS
0.85%

Original NVD Description

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.