Totolink · A3002Mu · CVE-2026-93739
**Name of the Vulnerable Software and Affected Versions**
Totolink A3002MU version Hh-B20211125.1046
**Description**
A remote buffer overflow exists in the `formWlAc()` function within the `/boafrm/formWlAc` file. This issue occurs when the `submit-url` argument is manipulated, potentially allowing an attacker to crash the system or execute arbitrary code.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the `/boafrm/formWlAc` file to minimize the risk of exploitation.