CVE-2026-105284
Totolink A3002MU Authentication Check boa sub_40FCFC improper authorization
CVSS Score
10.0
EPSS Score
0.0%
EPSS Percentile
0th
A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
| CWE | CWE-285 CWE-266 |
| Vendor | totolink |
| Product | a3002mu |
| Published | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for totolink a3002mu
Be the first to know when new critical vulnerabilities affecting totolink a3002mu are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Totolink / A3002MU
1.0.0-B20230403.1455
References
vuldb.com: https://vuldb.com/vuln/413465 vuldb.com: https://vuldb.com/vuln/413465/cti vuldb.com: https://vuldb.com/cve/CVE-2026-105284 vuldb.com: https://vuldb.com/submit/977217 gist.github.com: https://gist.github.com/H3rmesk1t/ac6e91a8fba51002be085755c8bf7d43 totolink.net: https://www.totolink.net/
Credits
๐ H3rmesk1t (VulDB User)