PT-2026-102920 · Totolink · N150Rt
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TOTOLINK N150RT (NTR150) version V3.4.0-B20201030
Description
A stack-based buffer overflow occurs in the web management interface when processing the rule-addition flow. The issue is located in the
sub 4156B0() function and is reachable via the '/boafrm/formPortFw' endpoint. It is triggered by the ip subnet and fw ip request parameters. A remote attacker could exploit this to cause a denial of service or execute arbitrary code.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N150Rt