Sceawere
Vulnerability Detail
CVE-2026-90604UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Totolink A3002MU Cross-Site Scripting
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.5
- Creation Date
- 3h ago
- Vendor
- Totolink
- Product
- A3002MU
- Attack Type
- Cross Site Scripting
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.5",
"pubDate": "2026-09-14T00:16:57.280Z",
"pubdate": "2026-09-14T00:16:57.280Z",
"executiveSummary": "A Cross-Site Scripting (XSS) vulnerability has been identified in the Totolink A3002MU router, specifically within the Anchor Tag Handler component.\nThis vulnerability allows unauthenticated remote attackers to inject malicious scripts into the web management interface.\nThe flaw stems from insufficient input sanitization of user-supplied data before it is processed and rendered by the device's web server.\nSuccessful exploitation can lead to unauthorized execution of arbitrary JavaScript in the context of an administrator's browser session.\nPotential impacts include session hijacking, unauthorized configuration changes, credential theft, or redirection to malicious sites.\nGiven that proof-of-concept exploit code is publicly available, the risk of exploitation by threat actors is high for internet-exposed devices.\nOrganizations using the affected hardware version (Hh-B20211125.1046) should prioritize network isolation and access restrictions until permanent patches are applied.",
"technicalDetails": "The vulnerability resides within the Anchor Tag Handler component of the Totolink A3002MU firmware (Hh-B20211125.1046), which fails to properly sanitize input parameters handled by the web management interface.\nThe root cause is an improper neutralization of input during web page generation, specifically concerning how the device parses and renders HTML anchor tags or related attributes when responding to client-side requests.\nThe attack flow initiates when an attacker crafts a malicious URI containing an injection payload, such as a script block or an event handler (e.g., onload, onerror), and transmits this to the vulnerable endpoint.\nBecause the Anchor Tag Handler component fails to apply context-aware output encoding or strict input validation, the malicious input is reflected directly into the Document Object Model (DOM) of the management interface.\nWhen an authenticated administrator views the affected interface element, the injected script executes within the security context of the router's web server. This allows the attacker to bypass standard Same-Origin Policy (SOP) constraints effectively.\nThe exploitation process typically involves the following steps: 1) Identification of an input vector within the device's web management interface that interacts with the Anchor Tag Handler. 2) Crafting a payload designed to manipulate the DOM or hijack the current session cookie. 3) Delivering the payload via a crafted URL or manipulated web request to the target system. 4) The device reflects the input, triggering script execution in the administrator's browser.\nThe impact is significant due to the nature of the interface. Since the web panel provides full administrative control over the network device, an attacker capable of performing XSS can leverage this to modify DNS settings, disable firewalls, create new administrative users, or update firmware configurations to achieve persistence.\nThis vulnerability is classified as remote because the management interface is often accessible via the Wide Area Network (WAN) or Local Area Network (LAN), depending on the configuration of the Remote Management settings on the router.\nPublicly disclosed exploit code confirms the feasibility of this attack, highlighting the need for immediate remediation for any device exposed to the public internet."
}