CVE-2026-93742
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/for
CVSS
9.9
Critical
EPSS
1.9%
p79
KEV
—
Exploit Today
24
0-100
Published: Sep 19, 2026 · Last modified: Sep 19, 2026 · CWE-74 · CWE-77
Not enough EPSS history yet.
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
- github.comhttps://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A3002MU/rce-formWsc.md
- vuldb.comhttps://vuldb.com/cve/CVE-2026-93742
- vuldb.comhttps://vuldb.com/submit/914021
- vuldb.comhttps://vuldb.com/vuln/407552
- vuldb.comhttps://vuldb.com/vuln/407552/cti
- www.totolink.nethttps://www.totolink.net/
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-879097.5 HIG43.5%
——13The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMagick command string executed via exec(), with only escapeshellcmd() applied to the whole command rather than quoting individual arguments. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server. escapeshellcmd() escapes shell metacharacters but does not prevent argument injection because spaces remain as argument separators, and the filename sanitization applied at the database layer is never applied to the physical temporary file path used for ImageMagick processing.14hCVE-2026-935336.3 MED64.6%
——19A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler. This manipulation of the argument host causes os command injection. It is possible to initiate the attack remotely. The pull request to fix this issue awaits acceptance.1dCVE-2026-886228.8 HIG63.8%
——19NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.2dCVE-2026-933718.3 HIG70.3%
——21A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manipulation of the argument params leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The name of the patch is c7ad3bd79c7c520a7d17e7f2ba19d962be8e7897. A patch should be applied to remediate this issue.2dCVE-2026-877019.6 CRI37.4%
——11Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.1dCVE-2026-858859.9 CRI43.7%
——13Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.1d