CVE-2026-94952: Buffer Overflow
A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formPortFw (port-forwarding configuration handler) and is triggered by the ipsubnet and fwip request parameters during the rule-addition flow.
Affected Software
Event History
Frequently Asked Questions
Which devices are affected?
The affected product is TOTOLINK N150RT (NTR150) running firmware V3.4.0-B20201030. The issue is in its web management interface.
What request fields reach the vulnerable code?
The vulnerable port-forwarding rule-addition handler is reachable at /boafrm/formPortFw. The ip_subnet and fw_ip request parameters trigger the stack-based buffer overflow.
What functionality should be restricted while the issue is being investigated?
Restrict access to the device's web management interface, particularly the port-forwarding configuration function and its rule-addition flow. The provided data identifies that flow as the reachable attack path.