PT-2026-104793 · Totolink · A3002Mu

·

CVE-2026-105286

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
A vulnerability was detected in Totolink A3002MU 1.0.0-B20230403.1455. This impacts the function sub 44B250 of the file /boafrm/formUploadFile of the component File Upload Handler. The manipulation of the argument filename results in path traversal. The attack can be executed remotely. The exploit is now public and may be used.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105286

Affected Products

A3002Mu