OS Command Injection Vulnerability in TOTOLINK N150RT Router
CVE-2026-100896
Key Information:
Badges
What is CVE-2026-100896?
A vulnerability has been discovered in the TOTOLINK N150RT router that allows for OS command injection via the web management interface. This issue is specifically related to the manipulation of the 'wlanif' argument in the /boafrm/formWlSiteSurvey function. Attackers can remotely exploit this weakness to execute arbitrary commands on the router's operating system, posing significant security risks. The exploit code has been publicly released, making it critical for users to apply necessary patches or mitigations to secure their devices.
Affected Version(s)
N150RT 3.4.0-B20201030
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
