Summary
CVE-2026-105284 is a critical improper-authorization (CWE-285) vulnerability in the TOTOLINK A3002MU wireless router, firmware version 1.0.0-B20230403.1455. A flaw in the /bin/boa web server’s authentication-check routine (sub_40FCFC) allows a remote, unauthenticated attacker to bypass session verification entirely and reach administrative and diagnostic request handlers. The issue carries the maximum CVSS score of 10.0 and is rated critical.
Technical details
- The
boaweb server validates a session by checking whether a stored login-IP value matches the requesting client’s IP and then reading an associated session token from a lookup table. - When a client has never logged in, the stored token buffer is empty; the authentication gate treats this empty buffer as a valid credential instead of rejecting the request, making the check "fail-open" for any client that has not authenticated.
- A remote, unauthenticated attacker can send requests directly to protected
/boafrm/*endpoints without any session cookie or credential and have them processed as if authenticated. - Publicly available proof-of-concept exploitation demonstrates reaching the
/boafrm/formSysCmdhandler, which executes attacker-supplied OS commands as root (e.g., via thesysCmd_pvalparameter), resulting in full device compromise. - Attack vector is network-based, requires no privileges and no user interaction, making exploitation straightforward against any internet-exposed device.
- Impact includes complete loss of confidentiality, integrity, and availability of the device — attackers can read/modify configuration, execute arbitrary commands, upload firmware, and pivot into the connected network.
Affected software
- TOTOLINK A3002MU, firmware version 1.0.0-B20230403.1455
Severity
- CVSS v3.1 Base Score: 10.0 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: No vendor-supplied patched firmware version has been identified at time of publication; check TOTOLINK’s official site for an updated firmware release for the A3002MU and apply it as soon as it becomes available.
- If no patch is available: Remove the device’s administrative web interface from direct internet exposure — place it behind a VPN or restrict access to trusted internal networks only via firewall rules.
- Disable remote/WAN management on the device if enabled.
- Monitor for unauthenticated requests to
/boafrm/*endpoints, particularlyformSysCmd, at the network perimeter. - Consider replacing or isolating end-of-life TOTOLINK devices that no longer receive security updates.

