Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-94952

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 TOTOLINK N150RT (NTR150) 设备固件 V3.4.0-B20201030 的 Web 管理界面中,存在一个基于栈的缓冲区溢出漏洞。该漏洞可通过路径 /boafrm/formPortFw(端口转发配置处理程序)访问,并在添加规则流程中,由 ip_subnet 和 fw_ip 请求参数触发。

AI Predicted 9.8 Difficulty: Easy EPSS 0.29% · P20

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
n/a n/a n/a affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-94952

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formPortFw (port-forwarding configuration handler) and is triggered by the ip_subnet and fw_ip request parameters during the rule-addition flow.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-94952

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-94952

请登录查看更多情报信息。

Other References for CVE-2026-94952 (1)

Same Patch Batch · n/a · 2026-09-29 · 20 CVEs total

CVE-2026-102248 7.3 HIGH Rebuild Login Endpoint login improper authentication
CVE-2026-102249 7.3 HIGH REBUILD file-editor-save authorization
CVE-2026-102247 6.8 MEDIUM FastAdmin Database Management database.php unnecessary privileges
CVE-2026-79348 4.3 MEDIUM KitchenAsty≤0.3.0预订接口越权访问漏洞
CVE-2026-67993 Uright静态回调登录CSRF漏洞
CVE-2026-67987 Ruby 3.1.x think-tag正则拒绝服务漏洞
CVE-2026-39117 AltumCode 66Uptime 54.0.0前代码执行漏洞
CVE-2026-79403 Kilo Code v7.4.1前权限端点任意代码执行
CVE-2026-79417 ArgusMonitor 7.4.02及之前版本TOCTOU致拒绝服务
CVE-2024-31027 Open eClass v.3.15用户注册XSS漏洞
CVE-2026-79534 mcp-filesystem-server v0.11.1 目录遍历
CVE-2026-79538 MetaMCP 2.4.22前mcp-proxy端点代码执行漏洞
CVE-2024-31026 eClass v3.15聊天框远程代码执行漏洞
CVE-2026-79537 MetaMCP 2.4.22 存在不安全的直接对象引用漏洞
CVE-2026-79536 Bytebase DBHub 1.2.0 SQL注入漏洞
CVE-2026-79535 VoiceMode 8.10.1及之前版本OS命令注入漏洞
CVE-2026-94953 TOTOLINK N150RT固件栈溢出漏洞
CVE-2026-94954 TOTOLINK N150RT 3.4.0 栈溢出漏洞
CVE-2026-77177 WhatsApp Open GenAI Stack Prompt注入致代码执行

IV. Related Vulnerabilities

V. Comments for CVE-2026-94952

No comments yet


Leave a comment