Impact
A weakness exists in the TOMOLINK N150RT firmware 3.4.0-B20201030 within the web management interface, specifically in the /boafrm/formWlSiteSurvey endpoint. By manipulating the wlanif parameter, an attacker can cause the system() function to execute arbitrary operating‑system commands supplied in the request. This results in remote code execution, enabling a malicious actor to gain full control over the device, modify configuration or install additional software.
Affected Systems
The affected product is the TOTOLINK N150RT router, running firmware version 3.4.0-B20201030. No other vendors or products are officially listed as impacted at this time.
Risk and Exploitability
The vulnerability has a CVSS score of 9.4, indicating critical severity. EPSS data is not available, but the exploit has been publicly released, meaning the practical risk is high. The attack vector is remote, occurring over the web interface; authentication status is not specified, suggesting that the vulnerability may be exploitable without credentials. The vulnerability is not listed in the CISA KEV catalog, but the severity and public availability warrant prompt action.
OpenCVE Enrichment