Overview
Researchers have disclosed CVE-2026-94952, a critical stack-based buffer overflow in the web management interface of the TOTOLINK N150RT (NTR150) wireless router, running firmware V3.4.0-B20201030. The flaw sits in the port-forwarding configuration handler at /boafrm/formPortFw, and is triggered by the ip_subnet and fw_ip request parameters during the rule-addition flow of the device's Boa-based web server.
The National Vulnerability Database (NVD) published the entry on September 29, 2026, assigning a CVSS 3.1 score of 9.8 (Critical) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — a network-reachable flaw that requires no authentication, no user interaction, and low attack complexity, with a full compromise of confidentiality, integrity, and availability if successfully exploited. Multiple third-party trackers, including VulDB, corroborate the finding and classify the underlying weakness as CWE-121 (Stack-based Buffer Overflow), with VulDB's own listing additionally tagging it under the broader CWE-120 (unchecked buffer copy) family.
The vulnerability was documented by researcher H3rmesk1t, who published a technical writeup via GitHub Gist alongside the disclosure. As of publication, NVD lists the record's analysis status as pending ("Received"/"Awaiting Analysis"), and no vendor advisory or patched firmware has been identified for the N150RT — the most recent firmware build TOTOLINK publishes for this model is the same V3.4.0-B20201030 release dated October 30, 2020, suggesting the device has received no updates in roughly six years and is effectively unmaintained.
Technical Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-94952 |
| Severity | Critical |
| CVSS Score | 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) |
| Attack Vector | Network |
| Authentication | Not required (PR:N) — no user interaction needed (UI:N) |
| CWE | CWE-121 — Stack-based Buffer Overflow (also tagged CWE-120 — Buffer Copy Without Checking Size of Input) |
| Component/Function | formPortFw handler, /boafrm/formPortFw (Port-Forwarding Configuration Handler), Boa embedded web server |
| Vulnerable Parameters | ip_subnet, fw_ip |
| Exploit Status | Technical writeup/PoC published by the discovering researcher; not listed on CISA's KEV catalog; no confirmed in-the-wild exploitation as of September 30, 2026 |
| Patch Status | No vendor-issued fix identified; latest available firmware matches the vulnerable build |
How It Works
The vulnerability class
CVE-2026-94952 is a classic stack-based buffer overflow (CWE-121): the formPortFw handler in the router's Boa-based CGI web application copies attacker-supplied form field data — here the ip_subnet and fw_ip values submitted when adding a port-forwarding rule — into a fixed-size buffer allocated on the stack, without first validating that the input length fits within that buffer. Overrunning the buffer corrupts adjacent stack memory, including (depending on the exact offset) saved registers or the function's return address.
The attack chain
- An attacker identifies a reachable TOTOLINK N150RT device — these are consumer/SOHO routers, so exposure ranges from local network access to, in misconfigured deployments, direct exposure of the admin interface to the internet.
- The attacker sends a crafted HTTP request to
/boafrm/formPortFwwith an oversizedip_subnetorfw_ipvalue, mimicking the normal port-forwarding "add rule" workflow. - Because the CVSS vector indicates no privileges required and no user interaction, the request does not need a valid admin session or any action from a legitimate user — this points to the handler being reachable without proper session/authentication enforcement, a recurring pattern in Boa-based TOTOLINK firmware.
- The oversized value overflows the fixed-size stack buffer during processing, corrupting stack memory. At minimum this crashes the Boa web server process (denial of service, requiring a device reboot to restore management access); with a carefully crafted payload that overwrites the return address, it can potentially redirect execution flow toward attacker-controlled code, yielding remote code execution on the router's underlying Linux/MIPS operating system.
Part of a broader disclosure batch
CVE-2026-94952 was not disclosed in isolation. The same researcher published closely related findings in the same N150RT firmware build around the same date, including CVE-2026-94953 (an authenticated stack overflow in the WEP key field of /boafrm/formAjaxSet), CVE-2026-94954 (a stack overflow in the URL-filter handler at /boafrm/formFilter), and CVE-2026-100896 (an OS command injection in /boafrm/formWlSiteSurvey, reportedly rated CVSS 9.9). This pattern — multiple unauthenticated or low-barrier memory-corruption bugs across different boafrm endpoints in the same firmware — is consistent with a systemic lack of input validation across the device's web management codebase rather than an isolated coding mistake. It also echoes an earlier, separate buffer overflow at this exact same /boafrm/formPortFw endpoint, CVE-2025-3988 (CVSS 8.8, via the service_type parameter), for which public proof-of-concept code was already circulating in 2025 — meaning this specific configuration handler has now been the subject of at least two distinct, unrelated overflow bugs.
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality | Rated High — successful exploitation could expose router configuration, credentials, or traffic routing details |
| Integrity | Rated High — an attacker able to achieve code execution could modify router configuration, DNS settings, or firmware behavior |
| Availability | Rated High — even a failed or partial exploitation attempt can crash the Boa web server or the device itself, disrupting network connectivity for every user behind the router |
| Network Position | A compromised home/SOHO router sits at the network perimeter — control over it enables traffic interception, DNS hijacking, and pivoting into the internal LAN |
| Botnet Recruitment Risk | Unauthenticated, network-reachable overflow bugs in consumer routers are a standard entry point for IoT botnets (Mirai-derived families have repeatedly targeted TOTOLINK devices); a public PoC raises the likelihood of automated scanning and exploitation |
| No Patch Available | Because TOTOLINK has not shipped updated firmware for the N150RT since 2020, affected devices have no remediation path other than replacement or network-level mitigation |
Recommendations
For anyone running a TOTOLINK N150RT
- Check your firmware version via the router's admin console and confirm whether it is running V3.4.0-B20201030 or earlier.
- Do not expose the router's web management interface to the internet. Disable remote/WAN-side administration if it is enabled.
- Restrict management access to trusted LAN devices only, and change default admin credentials if not already done.
- Consider replacing the device. Given the router's age (firmware last updated in 2020) and the absence of any vendor patch for this or the related CVEs disclosed alongside it, continued use of the N150RT as an internet-facing gateway carries materially elevated risk.
For managed service providers and IT teams
- Inventory any TOTOLINK N150RT (or related N1xx/A3xxx series) devices deployed at client sites or on guest/IoT network segments.
- Segment or firewall these devices so that even if the management interface is compromised, lateral movement into production networks is blocked.
- Monitor for anomalous traffic to/from known TOTOLINK management ports, and treat unexplained reboots of these devices as a potential indicator of exploitation attempts.
- Flag end-of-life consumer/SOHO networking hardware — including this device — for planned replacement as part of routine asset lifecycle management, rather than waiting for a vendor patch that may never arrive.
For detection
- Watch for unusually large
ip_subnetorfw_ipvalues, or malformed POST requests to/boafrm/formPortFw, in any logging or IDS/IPS coverage that can see traffic to affected devices. - Treat repeated Boa web server crashes or unexpected router reboots as a signal warranting investigation, particularly on internet-facing deployments.
Key Takeaways
- CVE-2026-94952 is a CVSS 9.8 critical, unauthenticated stack-based buffer overflow (CWE-121) in the TOTOLINK N150RT router's
/boafrm/formPortFwport-forwarding handler, disclosed September 29, 2026. - Exploitation requires no credentials and no user interaction, and can be triggered remotely via the
ip_subnetorfw_iprequest parameters, risking a crashed device or, in the worst case, remote code execution. - No vendor patch exists. TOTOLINK's most recent published firmware for this model dates to October 2020, the same build affected by this CVE — treat the device as effectively unsupported.
- The flaw was disclosed alongside three related CVEs (94953, 94954, and 100896) in the same firmware, and revisits an endpoint —
formPortFw— already hit by a separate overflow bug (CVE-2025-3988) in 2025, pointing to systemic input-validation weaknesses across this firmware's web management code. - No exploitation has been confirmed in the wild and the flaw is not on CISA's KEV catalog as of this writing, but a public technical writeup exists and consumer routers are a well-established target for automated botnet scanning.
- Given the lack of a patch path, mitigation means isolation or replacement — restrict management-interface exposure immediately and plan to retire affected hardware.
Sources
- NVD — CVE-2026-94952
- VulDB — CVE-2026-94952: TOTOLINK N150RT Port-Forwarding Configuration formPortFw Buffer Overflow
- strix.ai — CVE-2026-94952
- TheHackerWire — CVE-2026-94952: Buffer Overflow Analysis & Fix
CosmicBytez Labs will update this advisory if TOTOLINK publishes patched firmware or if active exploitation of CVE-2026-94952 is confirmed.