Sceawere
Vulnerability Detail
CVE-2026-105284UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Totolink A3002MU Improper Authorization Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 10
- Creation Date
- 10h ago
- Vendor
- Totolink
- Product
- A3002MU
- Attack Type
- Improper Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "10.0",
"pubDate": "2026-10-05T09:17:12.350Z",
"pubdate": "2026-10-05T09:17:12.350Z",
"executiveSummary": "A critical improper authorization vulnerability exists within the Totolink A3002MU firmware version 1.0.0-B20230403.1455. The vulnerability resides in the authentication check logic of the binary executable /bin/boa, specifically within the sub_40FCFC function.\nThis flaw allows a remote, unauthenticated attacker to bypass established security controls, potentially gaining unauthorized access to administrative functions or sensitive system configuration settings. The vulnerability stems from an insecure implementation of access control mechanisms that fail to properly validate user credentials or session tokens before granting access to protected resources.\nGiven that this vulnerability is accessible remotely and public exploit code is available, the risk to the device integrity and network security is high. Successful exploitation could lead to full system compromise, unauthorized configuration changes, or the interception of network traffic. Mitigation requires immediate attention to hardening network access and monitoring for anomalous traffic patterns directed at the management interface.",
"technicalDetails": "The vulnerability is localized within the /bin/boa web server process, which handles the administration interface for the Totolink A3002MU router. The specific flaw is located in the sub_40FCFC function, which serves as a core component for enforcing authentication checks across the device's web-based management platform.\nThe root cause of the vulnerability is a failure in the logic flow of sub_40FCFC, where the system fails to correctly verify the authenticity of incoming requests. During the request processing lifecycle, the function responsible for validating user sessions or credentials can be circumvented, allowing unauthorized HTTP requests to bypass the expected authentication barriers. This is often indicative of an insecure coding pattern where the authorization check is either skipped under certain request conditions or is susceptible to manipulation via specifically crafted inputs.\nThe attack flow commences when a remote attacker sends a maliciously crafted HTTP request to the device. Because the sub_40FCFC function does not properly validate the session state or authorization tokens before proceeding to the requested resource, the boa server process incorrectly assumes the request is legitimate. By manipulating specific HTTP headers or parameters, the attacker forces the system into an authorized state without providing valid credentials.\nThe exploit behavior involves leveraging the flaw to execute restricted function calls or access administrative pages that should be gated by the authentication mechanism. Upon successful bypass of the sub_40FCFC check, the attacker can interact with internal functions designed for privileged users. This level of access grants the capability to modify device configurations, change system passwords, update firmware settings, or potentially pivot into the internal network protected by the router.\nThe lack of robust input sanitization or state validation in the auth check function allows for the potential execution of unauthorized actions remotely. Since the vulnerability resides within a fundamental component of the /bin/boa binary, the exploit is not limited to a single endpoint, but rather affects all processes governed by this specific authentication routine. The publicly available exploit code automates this manipulation, making it trivial for an adversary to gain control over the affected device version."
}