CVE-2026-94953
Deferred Deferred - Pending Action

Stack-Based Buffer Overflow in TOTOLINK N150RT Firmware

Vulnerability report for CVE-2026-94953, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: MITRE

Description

A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formAjaxSet using the topicurl=setting/setWiFiRepeaterConfig branch and the ApCliWEPKey field.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
totolink n150rt 3.4.0-b20201030

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-94953 is a stack-based buffer overflow in the TOTOLINK N150RT router firmware V3.4.0-B20201030. It occurs in the web management interface at the /boafrm/formAjaxSet endpoint when the topicurl parameter is set to setting/setWiFiRepeaterConfig. The vulnerability is triggered by an unbounded strcpy() operation copying the ApCliWEPKey field into a 68-byte stack buffer without input validation. If ApCliWEPKey exceeds 67 bytes, it overflows, crashing the boa web server running as root.

Detection Guidance

To detect this vulnerability, check if your TOTOLINK N150RT router is running firmware version V3.4.0-B20201030. Test the vulnerable endpoint by sending a crafted request to /boafrm/formAjaxSet with topicurl=setting/setWiFiRepeaterConfig and a long ApCliWEPKey value. Monitor for crashes in the boa web server process.

  • Use curl to send a test payload: curl -X POST 'http://<router-ip>/boafrm/formAjaxSet' -d 'topicurl=setting/setWiFiRepeaterConfig&ApCliAuthMode=WEP&ApCliKeyFormat=0&ApCliWEPKey=<3000-byte-string>'
Impact Analysis

This vulnerability allows remote attackers to crash the router's web server by sending a maliciously crafted request. Since the boa server runs with root privileges, the crash could lead to denial of service (DoS) or potentially remote code execution (RCE) if the overflow overwrites critical stack data. Exploitation requires authentication to access the vulnerable endpoint.

Mitigation Strategies

Immediately update the router firmware to a patched version if available. Disable remote management access to the web interface if not required. Implement network segmentation to limit exposure of the vulnerable device. Monitor for unusual traffic patterns or crashes in the web server.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94953. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart