CVE-2026-94953: Buffer Overflow
Published Sep 29, 2026
·Updated
A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formAjaxSet using the topicurl=setting/setWiFiRepeaterConfig branch and the ApCliWEPKey field.
Affected Software
1 affected component
TOTOLINK N150RT (NTR150)=V3.4.0-B20201030
Event History
Sep 29, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which interface and input are affected?
The issue is in the web management interface, reachable at /boafrm/formAjaxSet through the topicurl=setting/setWiFiRepeaterConfig branch. The vulnerable input is the ApCliWEPKey field.
2
What firmware version is identified as vulnerable?
The affected firmware identified in the available data is TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030.