Description
A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Published: 2026-09-28
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution via OS command injection
Action: Immediate Patch
AI Analysis

Impact

A weakness exists in the TOMOLINK N150RT firmware 3.4.0-B20201030 within the web management interface, specifically in the /boafrm/formWlSiteSurvey endpoint. By manipulating the wlanif parameter, an attacker can cause the system() function to execute arbitrary operating‑system commands supplied in the request. This results in remote code execution, enabling a malicious actor to gain full control over the device, modify configuration or install additional software.

Affected Systems

The affected product is the TOTOLINK N150RT router, running firmware version 3.4.0-B20201030. No other vendors or products are officially listed as impacted at this time.

Risk and Exploitability

The vulnerability has a CVSS score of 9.4, indicating critical severity. EPSS data is not available, but the exploit has been publicly released, meaning the practical risk is high. The attack vector is remote, occurring over the web interface; authentication status is not specified, suggesting that the vulnerability may be exploitable without credentials. The vulnerability is not listed in the CISA KEV catalog, but the severity and public availability warrant prompt action.

Generated by OpenCVE AI on September 28, 2026 at 03:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router to the latest firmware released by TOTOLINK that addresses the /boafrm/formWlSiteSurvey issue.
  • If a firmware update is not yet available, restrict access to the web management interface to local‑network hosts or VPN connections only.
  • Disable or remove the WL-SPOTSURVEY functionality through the router’s configuration interface, if possible.
  • Use input validation on the wlanif parameter to reject non‑numeric values or marshal system calls in a safe manner.

Generated by OpenCVE AI on September 28, 2026 at 03:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink n150rt
Vendors & Products Totolink n150rt

Mon, 28 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Title TOTOLINK N150RT Web Management formWlSiteSurvey system os command injection
First Time appeared Totolink
Totolink n150rt Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:totolink:n150rt_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink n150rt Firmware
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Totolink N150rt N150rt Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T01:30:14.267Z

Reserved: 2026-09-27T08:32:34.128Z

Link: CVE-2026-100896

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T02:17:19.617

Modified: 2026-09-28T02:17:19.617

Link: CVE-2026-100896

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T03:30:07Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')