Sceawere
Vulnerability Detail
CVE-2026-105286UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Totolink A3002MU Path Traversal
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 9h ago
- Vendor
- Totolink
- Product
- A3002MU
- Attack Type
- Path Traversal
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was detected in Totolink A3002MU 1.0.0-B20230403.1455. This impacts the function sub_44B250 of the file /boafrm/formUploadFile of the component File Upload Handler. The manipulation of the argument filename results in path traversal. The attack can be executed remotely. The exploit is now public and may be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-10-05T10:16:41.247Z",
"pubdate": "2026-10-05T10:16:41.247Z",
"executiveSummary": "A critical path traversal vulnerability has been identified in the Totolink A3002MU router, specifically within the firmware version 1.0.0-B20230403.1455.\nThe vulnerability resides in the /boafrm/formUploadFile handler, which fails to adequately sanitize the filename argument during the file upload process.\nThis flaw permits a remote, unauthenticated attacker to escape the intended directory constraints and write arbitrary files to the underlying filesystem.\nThe risk implication is severe, as successful exploitation facilitates remote code execution (RCE) by overwriting critical system files or binary configuration scripts.\nGiven that the exploit is currently public, threat actors may leverage this flaw to gain persistent control over the device, bypass security controls, or facilitate lateral movement within the network.\nThe attack vector is remotely exploitable, requiring no prior authentication, thereby exposing the device to any actor with network access to the router's management interface.",
"technicalDetails": "The root cause of this vulnerability is improper input validation within the function sub_44B250, located inside the /boafrm/formUploadFile handler of the device's web server.\nDuring the file upload process, the application processes the 'filename' parameter provided in the HTTP request header or body without verifying the presence of directory traversal sequences, such as '../'.\nThe function sub_44B250 handles the internal routing of file uploads. When an attacker submits a crafted HTTP request, they can include '..' sequences in the filename argument, forcing the system's underlying file system API to resolve the destination path outside of the designated upload directory.\nThe attack flow follows a sequential pattern: 1) The attacker initiates an HTTP POST request targeting the /boafrm/formUploadFile endpoint. 2) The attacker injects malicious path traversal characters (e.g., ../../../etc/shadow or ../../../var/www/bin/payload) into the filename metadata associated with the uploaded binary. 3) The function sub_44B250 fails to sanitize the input, concatenating the malicious path with the base directory and committing the attacker-provided content to the target location.\nBecause this component executes with elevated system privileges, the capability to overwrite sensitive files allows an attacker to inject arbitrary binaries, modify startup scripts (such as those in /etc/init.d), or corrupt authentication configuration files to grant administrative access.\nThis vulnerability does not require authentication, meaning the impact is immediate upon receipt of the malicious request. The exposure is limited only by the reachability of the web interface; however, in many deployments, this interface is exposed directly to the wide area network (WAN) or accessible via the local area network (LAN), making it a significant vector for compromise.\nPost-exploitation, the attacker can establish persistence by modifying firmware-resident configuration files or executing malicious payloads that survive device reboots, effectively establishing a rootkit-like presence on the target hardware."
}