Sceawere
Vulnerability Detail
CVE-2026-100896UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
TOTOLINK N150RT OS Command Injection
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 6h ago
- Vendor
- TOTOLINK
- Product
- N150RT
- Attack Type
- OS Command Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-09-28T02:17:19.617Z",
"pubdate": "2026-09-28T02:17:19.617Z",
"executiveSummary": "A critical OS command injection vulnerability exists within the TOTOLINK N150RT firmware version 3.4.0-B20201030.\nThe vulnerability resides in the web management interface, specifically within the /boafrm/formWlSiteSurvey handler.\nBy manipulating the 'wlanif' argument, an unauthenticated remote attacker can inject and execute arbitrary system commands with elevated privileges.\nThe flaw stems from insufficient input sanitization of user-supplied data before passing it to system-level functions.\nSuccessful exploitation allows for complete system compromise, including unauthorized access to sensitive configurations, persistent backdoor installation, or potential lateral movement within the network.\nGiven that public exploit code is available, the risk to affected devices is considered high, as minimal technical sophistication is required for an adversary to gain control over the hardware.",
"technicalDetails": "The vulnerability is located in the /boafrm/formWlSiteSurvey component of the TOTOLINK N150RT web management interface.\nThe root cause is improper neutralization of special elements used in an OS command ('OS Command Injection') within the 'wlanif' parameter.\nDuring the site survey operation, the web server facilitates the execution of internal system binaries to scan for wireless networks. The application fails to validate or escape the 'wlanif' argument passed to this function.\nAn attacker can exploit this by crafting an HTTP request containing malicious command sequences, such as shell metacharacters (e.g., ';', '&', '|'), within the wlanif parameter value.\nUpon receiving the request, the underlying system process executes the injected string as part of the intended command chain. Because the web management process often runs with high-level system privileges, the injected commands inherit these permissions, allowing the attacker to interact directly with the device's operating system environment.\nAttack Flow: 1. The attacker targets the /boafrm/formWlSiteSurvey endpoint via a crafted HTTP POST or GET request. 2. The 'wlanif' parameter is modified to include an attacker-controlled payload. 3. The server-side script fails to sanitize the input, concatenating the malicious payload into a command string executed by the system shell. 4. The system executes the injected instructions, providing the attacker with code execution capability.\nThe exposure is network-based; since the management interface is typically accessible over the local area network (LAN) or potentially exposed via the Wide Area Network (WAN) depending on configuration, the attack vector is remote. No authentication is explicitly required to interact with this specific handler, significantly lowering the bar for exploitation.\nPost-exploitation impact includes full administrative control over the router, the ability to sniff local network traffic, redirection of traffic through malicious DNS settings, and the potential to use the device as a pivot point for further attacks on other internal network assets. The existence of public proof-of-concept exploits facilitates automated or opportunistic exploitation against vulnerable devices exposed to the internet."
}