External risk intelligence

TOTOLINK N150RT Firmware Stack Buffer Overflow Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-94952

The vulnerability resides in the web management interface of a network device, which is commonly accessible over the network to facilitate administration. While intended for internal use, such interfaces on consumer-grade routers are frequently exposed or reachable via the public internet in real-world deployments.

Buffer Overflow

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the web management interface of a specific router model. This issue, a stack-based buffer overflow, can be triggered remotely through the port-forwarding configuration. While the potential impact is severe, including unauthorized access and control, the primary concern for leadership at this stage is to determine if this specific technology is in use within the organization and assess any potential exposure.

  • Remote attackers can exploit this flaw.
  • It affects network management interfaces.
  • Confirm use and assess exposure impact.

Attack Path

How an attacker could exploit the issue

An attacker can reach the vulnerable code in the device's web management interface without needing any credentials. By sending a specially crafted request to the port forwarding configuration handler, an attacker can trigger a buffer overflow, potentially leading to a complete compromise of the device.

  • No authentication required.
  • Triggered by specific request parameters.
  • Leads to device compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to remotely execute arbitrary code by sending specially crafted requests to the device's web management interface. The attack targets the port-forwarding configuration handler, specifically when adding new rules using the `ip_subnet` and `fw_ip` parameters. Successful exploitation may lead to a complete compromise of the affected device.

  • Device configuration and control.
  • Network requests to vulnerable endpoint.
  • Full device compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The web management interface of TOTOLINK N150RT devices presents a stack-based buffer overflow vulnerability. Initial triage should focus on identifying all instances of this firmware, assessing their network exposure and criticality, and locating the accountable owner for remediation.

  • Identify affected device owners.
  • Verify external reachability and business impact.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TOTOLINK N150RT router?

The TOTOLINK N150RT is a consumer-grade wireless network router. It manages internet traffic for connected devices and provides a web-based administration interface that allows users to configure settings like port forwarding, security protocols, and network connections directly through a web browser.

How does this stack-based buffer overflow work?

This vulnerability, classified as CWE-121, occurs when the router's software tries to store more data in a memory space than it is designed to hold. In CVE-2026-94952, the web interface fails to properly validate the size of input provided by a user. When an attacker sends oversized data to specific configuration parameters, it overwrites adjacent memory, which can cause the device to crash or allow the execution of unauthorized code.

What triggers this vulnerability in the firmware?

The vulnerability is triggered when an attacker interacts with the port-forwarding configuration handler at the /boafrm/formPortFw route. Specifically, providing malicious input for the ip_subnet or fw_ip parameters during the rule-addition process initiates the flaw. Normal network traffic passing through the router is not affected; the issue is isolated to interactions with the management interface itself.

Is my device at risk if it is not on the internet?

According to Halo Surface Signal, while this management interface is intended for internal administration, many consumer routers are inadvertently accessible from the public internet. If your device is reachable from outside your local network, your risk is significantly higher. Even if it is strictly internal, any user or compromised system on your local network could attempt to reach this interface.

How should I handle CVE-2026-94952?

Begin by auditing your environment to locate any instances of the TOTOLINK N150RT running firmware V3.4.0-B20201030. Once identified, verify if these devices are exposed to the internet or accessible to unauthorized local users. Prioritize restricting access to the web management interface, such as disabling remote management features, and prepare to update or replace the hardware if vendor patches become available.

References