CVE-2026-94954: Buffer Overflow
Published Sep 29, 2026
·Updated
A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formFilter (access-control / URL filter configuration handler) and is triggered by the url request parameter when the addFilterUrl (or addFilterUrlFlag) action flag is set.
Affected Software
1 affected component
TOTOLINK N150RT (NTR150) firmware=V3.4.0-B20201030
Event History
Sep 29, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:17 PM
Description
Frequently Asked Questions
1
Which devices and firmware are identified as affected?
The affected product identified is the TOTOLINK N150RT (NTR150) running firmware V3.4.0-B20201030.
2
What must an attacker send to reach the vulnerable code path?
The attacker must target the web management route /boafrm/formFilter and provide the url request parameter while setting either the addFilterUrl or addFilterUrlFlag action flag.
3
Which management feature is involved?
The vulnerable handler is used for access-control and URL filter configuration.