OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-93740 (CVSS 9.3)

NVD · officialPublished Sep 18, 2026Risk 50/100EPSS 0.6%

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

CVSS
9.3
AV:NetworkAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source