Skip to finding
important · Firmware / Edge

Any LAN client can bypass the TOTOLINK A3002MU login and execute shell commands as root.

Affects

TOTOLINK A3002MU, a dual-band home and small-office Wi-Fi router running embedded Linux firmware.

A fail-open session check exposes the Boa handlers; formWsc then passes shell-bearing peerPin input to system() as root.

Detail and 2 sources

Public exploit code is available and no patch was identified, but the path is confined to LAN reachability on one obscure router.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 19, 2026