CVE-2026-6194 Details
Description
A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_410188 of the file /boafrm/formWlanSetup of the component HTTP Request Handler. This manipulation of the argument wan-url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
A stack-based buffer overflow vulnerability has been identified in the Totolink A3002MU router, specifically in the firmware version B20211125.1046. The issue arises in the HTTP request handler function 'formWlanSetup', located in the binary file '/bin/boa'. The vulnerability is triggered by the 'wan-url' parameter, which is accepted from user input without proper length validation. This oversight allows an attacker to send a maliciously long 'wan-url' string, causing the buffer to overflow, corrupt adjacent memory, and potentially leading to a denial-of-service condition. The vulnerability can be exploited remotely, and a public proof-of-concept exploit is available.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 13, 2026CISA-ADP
Assessed Apr 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/zhuchan770/vulnerability/blob/main/A3002MU/formWlanSetup/ToToLinkA3002MU%20formWlanSetup%20339996b67c9780caafb2d351dfd8a889.md | [email protected] | ExploitTechnical Description |
| https://vuldb.com/submit/797452 | [email protected] | Technical Description |
| https://vuldb.com/vuln/357116 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/vuln/357116/cti | [email protected] | Content Wall |
| https://www.totolink.net/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Totolink A3002MU | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 13, 2026 | New CVE Received | [email protected] |
Volerion