CVE-2026-94952
published 2026-09-29CVE-2026-94952: A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable…
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.29%
20.2th percentile
A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formPortFw (port-forwarding configuration handler) and is triggered by the ip_subnet and fw_ip request parameters during the rule-addition flow.
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
TOTOLINK N150RT up to 3.4.0-B20201030 Port-Forwarding Configuration /boafrm/formPortFw ip_subnet/fw_ip buffer overflow
vuldb·2026-09-29
CVE-2026-94952 TOTOLINK N150RT up to 3.4.0-B20201030 Port-Forwarding Configuration /boafrm/formPortFw ip_subnet/fw_ip buffer overflow
A vulnerability described as very critical has been identified in TOTOLINK N150RT up to 3.4.0-B20201030. This impacts the function formPortFw of the file /boafrm/formPortFw of the component Port-Forwarding Configuration Handler. Such manipulation of the argument ip_subnet/fw_ip leads to buffer overflow.
This vulnerability is traded as CVE-2026-94952. The attack may be launched remotely. There is no exploit available.
GHSA
A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030.
ghsa_unreviewed·2026-09-29
CVE-2026-94952 [CRITICAL] CWE-121 A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030.
A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formPortFw (port-forwarding configuration handler) and is triggered by the ip_subnet and fw_ip request parameters during the rule-addition flow.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-29
Published