CVE-2026-15271 Details
Description
A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906. Affected by this issue is some unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. The manipulation leads to least privilege violation. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitation is known to be difficult.
A vulnerability has been identified in several TOTOLINK router models, including the A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10, and EX200, all running versions prior to 20260906. The issue arises from an unknown functionality in the web interface configuration file, which can be manipulated to violate least privilege access. This vulnerability can be exploited remotely, although the exploitation process is considered complex and challenging.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 9, 2026CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://app.notion.com/p/A3000RU-V5-9c-5185-37a1f5ba989080d38bb6ca58b2a98c64?source=copy_link | [email protected] | Permission RequiredVendor |
| https://vuldb.com/cve/CVE-2026-15271 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/852316 | [email protected] | Permission Required |
| https://vuldb.com/submit/852317 | [email protected] | Permission Required |
| https://vuldb.com/submit/852318 | [email protected] | Permission Required |
| https://vuldb.com/submit/852319 | [email protected] | Permission Required |
| https://vuldb.com/submit/852320 | [email protected] | Permission Required |
| https://vuldb.com/submit/852321 | [email protected] | Permission Required |
| https://vuldb.com/submit/852323 | [email protected] | Permission Required |
| https://vuldb.com/vuln/377214 | [email protected] | Content Wall |
| https://vuldb.com/vuln/377214/cti | [email protected] | Content Wall |
| https://www.totolink.net/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-272 | Least Privilege Violation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| TOTOLINK A3000RU | <= 20260906 |
CPE
Remediation
| |
| TOTOLINK A3100R | <= 20260906 |
CPE
Remediation
| |
| TOTOLINK A950RG | <= 20260906 |
CPE
Remediation
| |
| TOTOLINK AC1200T10 | <= 20260906 |
CPE
Remediation
| |
| TOTOLINK CP450 | <= 20260906 |
CPE
Remediation
| |
| TOTOLINK CS185R_T10 | <= 20260906 |
CPE
Remediation
| |
| TOTOLINK EX200 | <= 20260906 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 3, 2026 | CVE Modified | [email protected] |
| Sep 3, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |
Volerion