CVE-2026-93742

Severity CVSS v4.0:
HIGH
Type:
CWE-74 Injection
Publication date:
19/09/2026
Last modified:
21/09/2026

Description

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.