CVE-2026-93742
CRITICAL
NVD
CVSS Score
9.9
Severity
CRITICAL
Published
Sep 19, 2026
Vendor
unknown
Description
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.