Executive brief
TOTOLINK N150RT is a wireless router that provides web-based management for network configuration. An authenticated attacker can inject arbitrary operating system commands through the wireless interface configuration form, allowing them to execute commands with root privileges on the router. This enables complete device compromise, including data theft, device takeover, or use as a network attack platform.
Technical details
The vulnerability is an OS command injection (CWE-78) in the /boafrm/formWlSiteSurvey handler of the web management interface. The wlanif parameter is read from an authenticated POST request and concatenated directly into six separate system() shell commands without any input validation, whitelist enforcement, or character escaping. An authenticated attacker can supply shell metacharacters (e.g., wlanif=wlan0;command) to execute arbitrary commands as root, or supply values exceeding 31 bytes to trigger a secondary stack buffer overflow.
Affected products
- TOTOLINK N150RT 3.4.0-B20201030
Timeline
- 2026-09-28: disclosed: Vulnerability disclosed in NVD and public PoC
- 2026-08-07: other: Public PoC published on GitHub by H3rmesk1t