Totolink · N150Rt · CVE-2026-94954
**Name of the Vulnerable Software and Affected Versions**
TOTOLINK N150RT (NTR150) version V3.4.0-B20201030
**Description**
A stack-based buffer overflow occurs in the web management interface. This issue is reachable via the '/boafrm/formFilter' endpoint, which handles access-control and URL filter configurations. The flaw is triggered by the `url` request parameter when the `addFilterUrl` or `addFilterUrlFlag` action flags are set. A stack-based buffer overflow is a condition where a program writes more data to a buffer located on the stack than it can hold, potentially leading to crashes or arbitrary code execution.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the `url` parameter in the '/boafrm/formFilter' endpoint to minimize the risk of exploitation.