CVE-2026-94952
A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formPortFw (port-forwarding configuration handler) and is triggered by the ip_subnet and fw_ip request parameters during the rule-addition flow.
- Published Sep 29, 2026
- CVSS 9.8 critical
- 0.3% chance of exploitation in the next 30 days (EPSS)