CVE-2026-94952 Overview
CVE-2026-94952 is a stack-based buffer overflow vulnerability in the web management interface of the TOTOLINK N150RT (NTR150) router running firmware version V3.4.0-B20201030. The flaw resides in the port-forwarding configuration handler exposed at the /boafrm/formPortFw endpoint. Attackers can trigger the overflow by supplying oversized values in the ip_subnet and fw_ip request parameters during the rule-addition flow. The condition corresponds to [CWE-121] stack-based buffer overflow and affects an internet-facing management surface commonly deployed in home and small-office environments.
Critical Impact
Successful exploitation can corrupt the router stack, enabling denial of service and potentially arbitrary code execution on the embedded device.
Affected Products
- TOTOLINK N150RT (NTR150) router
- Firmware version V3.4.0-B20201030
- Web management component /boafrm/formPortFw (port-forwarding handler)
Discovery Timeline
- 2026-09-29 - CVE-2026-94952 published to NVD
- 2026-09-29 - Last updated in NVD database
Technical Details for CVE-2026-94952
Vulnerability Analysis
The TOTOLINK N150RT web management interface is served by the boa HTTP daemon, which dispatches port-forwarding rule submissions to the formPortFw handler. When an authenticated or otherwise reachable user submits a port-forwarding rule, the handler reads the ip_subnet and fw_ip parameters from the HTTP request and copies them into fixed-size stack buffers without validating input length. Supplying values longer than the destination buffer overwrites adjacent stack memory, including saved registers and the return address on the MIPS-based device. See the public proof-of-concept gist for request details.
Root Cause
The root cause is missing bounds checking on user-controlled parameters prior to string copy operations, consistent with unsafe use of functions such as strcpy or sprintf against fixed stack buffers. Neither ip_subnet nor fw_ip is validated for length or format before being written into the stack frame of the rule-addition routine.
Attack Vector
An attacker with access to the router web management interface sends a crafted HTTP POST request to /boafrm/formPortFw containing oversized ip_subnet and fw_ip values. The overflow overwrites the saved return address, causing the boa process to crash or, with precise payload construction on the MIPS architecture, redirect execution to attacker-controlled shellcode. Because the management interface may be reachable from the LAN or, if remote administration is enabled, from the WAN, exposure varies by deployment.
No verified exploit code is reproduced here. The referenced public gist documents the vulnerable request structure.
Detection Methods for CVE-2026-94952
Indicators of Compromise
- HTTP POST requests to /boafrm/formPortFw containing unusually long ip_subnet or fw_ip parameter values.
- Unexpected reboots, boa process crashes, or loss of management interface availability on TOTOLINK N150RT devices.
- New or unauthorized port-forwarding rules appearing in the router configuration.
Detection Strategies
- Inspect network traffic to router management interfaces for POST requests to /boafrm/formPortFw where parameter lengths exceed typical IPv4 subnet or address values.
- Correlate router syslog output with network telemetry to identify crashes coincident with malformed HTTP requests.
- Alert on any exposure of the TOTOLINK web management interface to untrusted networks, including the WAN.
Monitoring Recommendations
- Forward router logs and NetFlow data to a centralized analytics platform for retention and correlation across devices.
- Baseline normal administrative traffic to the router and flag deviations in request size, source, or frequency.
- Track firmware version inventory to identify unpatched N150RT devices still running V3.4.0-B20201030.
How to Mitigate CVE-2026-94952
Immediate Actions Required
- Disable remote (WAN-side) management on all TOTOLINK N150RT devices to reduce exposure of the vulnerable endpoint.
- Restrict LAN access to the web management interface using ACLs or VLAN segmentation so only trusted administrative hosts can reach it.
- Change default administrative credentials and require strong, unique passwords for router administration.
Patch Information
No vendor patch or fixed firmware version is referenced in the available advisory data for CVE-2026-94952. Monitor the TOTOLINK support portal for firmware updates addressing the formPortFw handler and apply them once released.
Workarounds
- Block external access to TCP ports serving the router HTTP management interface at the network edge.
- Replace end-of-life or unsupported TOTOLINK N150RT hardware with a currently supported router if no firmware fix becomes available.
- Avoid adding port-forwarding rules through the web interface until a patched firmware image is installed.
# Example: restrict router management interface to a single admin host using iptables on an upstream firewall
iptables -A FORWARD -p tcp -d <router_ip> --dport 80 -s <admin_workstation_ip> -j ACCEPT
iptables -A FORWARD -p tcp -d <router_ip> --dport 80 -j DROP
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.