CVE-2026-94953
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formAjaxSet using the topicurl=setting/setWiFiRepeaterConfig branch and the ApCliWEPKey field.
Published 2026-09-29. Last modified 2026-09-30.