CVE-2026-94954 Overview
CVE-2026-94954 is a stack-based buffer overflow vulnerability in the web management interface of the TOTOLINK N150RT (NTR150) router running firmware version V3.4.0-B20201030. The flaw resides in the /boafrm/formFilter route, which handles access-control and URL filter configuration. Attackers trigger the overflow through the url request parameter when the addFilterUrl or addFilterUrlFlag action flag is set. Successful exploitation corrupts stack memory in the router's HTTP daemon, enabling denial of service or potential arbitrary code execution on the embedded device.
Critical Impact
Attackers with access to the web management interface can overflow the stack via a crafted url parameter, potentially achieving code execution on the router with elevated privileges.
Affected Products
- TOTOLINK N150RT (NTR150) router
- Firmware version V3.4.0-B20201030
- /boafrm/formFilter URL filter configuration handler
Discovery Timeline
- 2026-09-29 - CVE-2026-94954 published to NVD
- 2026-09-29 - Last updated in NVD database
Technical Details for CVE-2026-94954
Vulnerability Analysis
The vulnerability is a classic stack-based buffer overflow [CWE-121] in the router's HTTP configuration handler. The /boafrm/formFilter endpoint processes URL filter rules submitted through the web management interface. When the request includes the addFilterUrl or addFilterUrlFlag action flag, the handler reads the url parameter from the POST body and copies it into a fixed-size stack buffer without validating length. Supplying an oversized value overwrites adjacent stack data, including the saved return address of the calling function.
Embedded devices like the N150RT typically run the web daemon as root on a MIPS or ARM SoC without modern exploit mitigations such as ASLR or stack canaries. This dramatically simplifies exploitation and increases the impact of a successful overflow.
Root Cause
The root cause is missing bounds checking on user-supplied input inside the formFilter handler within the boa-based web server. The developer used an unsafe string copy operation to move the url POST parameter into a stack buffer, trusting client-supplied length. No input sanitization or maximum-length enforcement is applied before the copy.
Attack Vector
An attacker sends a crafted HTTP POST request to /boafrm/formFilter with the addFilterUrl (or addFilterUrlFlag) action flag and an oversized url parameter. The request must reach the web management interface, which is typically accessible from the LAN and, in some deployments, exposed to the WAN. Depending on authentication state and network exposure, an unauthenticated or authenticated attacker on the same network segment can trigger the overflow. Reference exploitation details are available in the published GitHub Gist Exploit Code.
No verified proof-of-concept code is reproduced here. See the linked technical reference for exploitation details.
Detection Methods for CVE-2026-94954
Indicators of Compromise
- HTTP POST requests to /boafrm/formFilter containing unusually long url parameter values, particularly with lengths exceeding a few hundred bytes.
- Requests to /boafrm/formFilter that include the addFilterUrl or addFilterUrlFlag action flag from unexpected client IP addresses.
- Unexpected reboots, crashes, or unresponsiveness of the router's web management interface following inbound HTTP traffic.
Detection Strategies
- Inspect HTTP traffic destined for the router management interface for oversized POST bodies and non-printable characters inside URL filter parameters.
- Deploy network intrusion detection signatures that flag POST requests to /boafrm/formFilter where the url field exceeds a defined length threshold.
- Correlate router availability changes with preceding administrative HTTP requests to identify potential exploitation attempts.
Monitoring Recommendations
- Log and alert on all administrative access to the router web interface, especially from non-management VLANs or external addresses.
- Monitor router uptime and syslog output for abnormal restarts of the boa web daemon.
- Enforce management-plane segmentation and audit any HTTP or HTTPS access to router configuration endpoints.
How to Mitigate CVE-2026-94954
Immediate Actions Required
- Disable remote (WAN-side) access to the web management interface of the N150RT immediately.
- Restrict LAN access to the router administration interface to a dedicated management workstation or VLAN.
- Change default administrative credentials and require strong passwords to reduce the pool of attackers able to reach the vulnerable handler in authenticated configurations.
Patch Information
No vendor patch has been published for firmware V3.4.0-B20201030 at the time of NVD publication on 2026-09-29. Monitor the TOTOLINK support portal for a firmware update addressing the /boafrm/formFilter handler. If the device is end-of-life or an update is not forthcoming, plan replacement with a supported router.
Workarounds
- Block inbound HTTP and HTTPS traffic to the router's WAN interface using upstream firewall rules.
- Place the router behind a segmented management network and permit configuration traffic only from trusted hosts.
- Disable the URL filter configuration feature if not required, reducing the exposure of the vulnerable addFilterUrl code path.
# Example upstream firewall rule to block WAN access to the router web UI
iptables -A FORWARD -p tcp -d <router-wan-ip> --dport 80 -j DROP
iptables -A FORWARD -p tcp -d <router-wan-ip> --dport 443 -j DROP
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.