Skip to main content
Vulnerability Database/CVE-2026-94953

CVE-2026-94953: TOTOLINK N150RT Buffer Overflow Vulnerability

CVE-2026-94953 is a stack-based buffer overflow flaw in TOTOLINK N150RT firmware that can be exploited through the web management interface. This post covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-94953 Overview

CVE-2026-94953 is a stack-based buffer overflow vulnerability in the web management interface of the TOTOLINK N150RT (NTR150) router running firmware version V3.4.0-B20201030. The flaw is reachable through the /boafrm/formAjaxSet endpoint when the topicurl=setting/setWiFiRepeaterConfig branch is invoked. Attackers can trigger the overflow by supplying an oversized value in the ApCliWEPKey field. Successful exploitation corrupts stack memory in the boa web server process, which typically runs with root privileges on TOTOLINK devices.

Critical Impact

Stack corruption in an authenticated router management endpoint can lead to arbitrary code execution or persistent denial of service against the affected device.

Affected Products

  • TOTOLINK N150RT (NTR150) router
  • Firmware version V3.4.0-B20201030
  • Web management interface component (boa HTTP server, /boafrm/formAjaxSet handler)

Discovery Timeline

  • 2026-09-29 - CVE-2026-94953 published to the National Vulnerability Database
  • 2026-09-29 - Last updated in NVD database

Technical Details for CVE-2026-94953

Vulnerability Analysis

The vulnerability resides in the request handler that services the /boafrm/formAjaxSet URI on the TOTOLINK N150RT web management interface. When the request parameter topicurl is set to setting/setWiFiRepeaterConfig, the handler parses configuration fields intended for the WiFi repeater setup, including ApCliWEPKey. The handler copies the attacker-supplied ApCliWEPKey value into a fixed-size stack buffer without validating the input length. Supplying a value larger than the destination buffer overwrites adjacent stack data, including saved return addresses and function pointers. Refer to the GitHub Gist PoC Code for technical proof-of-concept details.

Root Cause

The root cause is missing bounds checking on user-controlled input before it is copied into a stack-allocated buffer [CWE-121]. The setWiFiRepeaterConfig branch trusts the length of the ApCliWEPKey field and passes it directly into an unsafe string-copy operation. Firmware written in C for resource-constrained routers frequently relies on functions such as strcpy or sprintf, which do not enforce destination-buffer limits.

Attack Vector

An attacker with reachability to the router's web management interface can send a crafted HTTP POST request to /boafrm/formAjaxSet. The request specifies topicurl=setting/setWiFiRepeaterConfig and includes an oversized ApCliWEPKey parameter. If the interface is exposed to the LAN, any adjacent user can attempt exploitation. If management is exposed to the WAN, exploitation is reachable from the internet. Because boa runs as root on TOTOLINK firmware, control-flow hijack results in root-level execution on the device.

No verified exploitation code is reproduced here. See the GitHub Gist PoC Code for the researcher's proof of concept.

Detection Methods for CVE-2026-94953

Indicators of Compromise

  • HTTP POST requests to /boafrm/formAjaxSet containing the parameter topicurl=setting/setWiFiRepeaterConfig
  • Requests where the ApCliWEPKey field length exceeds valid WEP key sizes (5, 10, 13, or 26 characters)
  • Unexpected reboots, crashes, or watchdog resets on TOTOLINK N150RT devices
  • Unauthorized configuration changes to WiFi repeater settings

Detection Strategies

  • Inspect HTTP request bodies at network chokepoints for oversized ApCliWEPKey values addressed to TOTOLINK management interfaces.
  • Correlate device availability telemetry with inbound management-plane traffic to surface exploitation attempts that crash the boa process.
  • Alert on any request to /boafrm/formAjaxSet originating from untrusted network segments.

Monitoring Recommendations

  • Log and review all HTTP requests to router management endpoints from client subnets.
  • Monitor for repeated connection resets or 5xx responses from the router web interface, which can indicate crashes.
  • Track outbound connections from the router to unfamiliar hosts, which can indicate post-exploitation command-and-control activity.

How to Mitigate CVE-2026-94953

Immediate Actions Required

  • Disable remote WAN management on the TOTOLINK N150RT to eliminate internet-facing exposure of /boafrm/formAjaxSet.
  • Restrict LAN-side access to the management interface using firewall or VLAN segmentation so that only authorized administrator hosts can reach the router UI.
  • Change default and existing administrator credentials, and audit configuration for unauthorized changes to WiFi repeater settings.
  • Where feasible, replace the TOTOLINK N150RT with a supported device, as this hardware line has a history of unpatched web-interface vulnerabilities.

Patch Information

At the time of publication, no vendor advisory or firmware update addressing CVE-2026-94953 is listed in the enriched CVE data. Administrators should monitor the TOTOLINK support portal for a fixed firmware release superseding V3.4.0-B20201030.

Workarounds

  • Place the router management interface behind a management VLAN reachable only through a jump host.
  • Block inbound TCP traffic to the router's HTTP management port from the WAN at the upstream firewall.
  • Avoid configuring the WiFi repeater feature from untrusted networks, and disable the repeater function when not in use.
bash
# Example: block WAN-side access to the router management interface
# Replace <router_ip> and <mgmt_port> with values for the environment
iptables -A INPUT -i <wan_iface> -p tcp --dport <mgmt_port> -j DROP

# Example: restrict LAN access to a single admin workstation
iptables -A INPUT -i <lan_iface> -p tcp --dport <mgmt_port> \
  ! -s <admin_workstation_ip> -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.