Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105284— Totolink A3002MU Authentication Check boa sub_40FCFC improper authorization

Quick assessment

Affected
Totolink A3002MU
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在Totolink A3002MU版本1.0.0-B20230403.1455中发现了安全弱点。受影响的组件为“认证检查”模块中文件 的函数 。攻击者可通过构造恶意操作触发该漏洞,导致身份验证机制失效,从而绕过授权控制。该漏洞可从远程发起攻击,且相关利用代码已公开,可能被用于实际攻击。

CVSS 10.0 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105284

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Totolink A3002MU Authentication Check boa sub_40FCFC improper authorization
Source: CVE Program / CVE List V5
Vulnerability Description
A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Totolink A3002MU 1.0.0-B20230403.1455 cpe:2.3:a:totolink:a3002mu:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-105284

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105284

请登录查看更多情报信息。

Other References for CVE-2026-105284 (4)

Same Patch Batch · Totolink · 2026-10-05 · 3 CVEs total

CVE-2026-105285 10.0 CRITICAL Totolink A3002MU QoS Rule formIpQoS stack-based overflow
CVE-2026-105286 6.3 MEDIUM Totolink A3002MU File Upload formUploadFile sub_44B250 path traversal

IV. Related Vulnerabilities

V. Comments for CVE-2026-105284

No comments yet


Leave a comment