Skip to content
eastbaycyber

CVE-2026-100896: TOTOLINK N150RT Command Injection

CVE explainers 8 min read
SR
Security Research Desk Expert reviewed
Threat intelligence · Human-verified · Updated 2026-09-28
▲ Escalation ViewOne CVE, briefed at three altitudes — skim the Brief, weigh the Impact, or work the Runbook. The way a SOC actually reads it.
CISOBrief · 30-second brief

TL;DR - CVE-2026-100896 is a critical remote OS-command-injection flaw in TOTOLINK N150RT firmware 3.4.0-B20201030. - NVD reports a public exploit reference; no fixed firmware version has been identified. - Restrict Web Management Interface access immediately and assess replacement if the device is unsupported.

Summary

Field Value
CVE CVE-2026-100896
Product TOTOLINK N150RT
Affected firmware 3.4.0-B20201030
CVSS base score 9.9, Critical
Attack vector Remote; exact CVSS vector string was not available in the retrieved record
Authentication required Not specified in the available sources
Patch available No vendor-confirmed patch or fixed version identified
Public exploit Yes, according to NVD
CISA KEV status Not listed

CVE-2026-100896 affects the TOTOLINK N150RT Web Management Interface. The vulnerable functionality is associated with /boafrm/formWlSiteSurvey, where the wlanif argument reaches a system command invocation without sufficient protection against OS command injection. A successful attacker may be able to execute operating-system commands in the security context of the web-management process.

Learn more about the underlying vulnerability class in our command injection glossary.

Routers with Internet-facing administration enabled deserve immediate attention. Available research identifies remote exploitability and a public exploit reference, but does not establish whether authentication is required, what privilege level is needed, or whether the vulnerable endpoint is reachable before login. Treat those details as unknown until vendor documentation, controlled testing, or analysis of the referenced proof of concept confirms them.

AnalystImpact · assess the risk

Root Cause

The root cause is insufficient validation or sanitization of the wlanif input parameter before it is passed to the affected system function. The vulnerable code path is located in the file /boafrm/formWlSiteSurvey, part of the router’s Web Management Interface. Input that should represent a wireless-interface value can therefore be interpreted as operating-system command syntax.

This type of vulnerability is dangerous on embedded network equipment because the management process may have broad access to network configuration, firewall rules, DNS settings, wireless settings, and firmware or startup components. The available sources do not identify the exact execution user, shell invocation, persistence mechanism, or command restrictions. Treat those details as unknown rather than inferring them from the CVSS score.

A compromise could affect more than the router itself. An attacker may be able to alter DNS behavior, redirect traffic, weaken firewall policy, modify wireless configuration, scan internal networks, or use the router as an initial foothold. Router logs can be incomplete, and firmware may not preserve forensic evidence reliably. Unexplained configuration changes or unusual outbound traffic should therefore be treated as possible compromise indicators.

Who’s Exposed

The specifically identified affected product is the TOTOLINK N150RT running firmware version 3.4.0-B20201030. The retrieved vulnerability data does not provide a broader version range. Verify earlier firmware builds, later firmware builds, regional variants, and hardware revisions individually rather than automatically classifying them as affected or safe.

Product Affected version Fixed version
TOTOLINK N150RT 3.4.0-B20201030 Not identified in the available sources

Exposure depends heavily on management-plane configuration. Devices with Web Management Interface access exposed to the public Internet are at greatest risk. Devices whose administration interface is reachable only from a trusted LAN or dedicated management VLAN have a smaller attack surface, but they remain vulnerable if an attacker compromises an internal host, gains wireless access, or reaches the management network through another weakness.

Inventory both production and “small office” equipment. N150RT devices may be deployed outside formal IT procurement processes, including branch offices, temporary sites, home offices, and unmanaged network closets. Search asset inventories, DHCP records, wireless controller records, ISP-managed equipment lists, and Internet scans of organizational address space where permitted.

Severity Breakdown

NVD assigns CVE-2026-100896 a CVSS base score of 9.9, placing it in the Critical category. The score reflects the serious impact of remotely exploitable command injection on a network appliance. Arbitrary operating-system commands could affect confidentiality, integrity, and availability through network interception, configuration tampering, service disruption, or device takeover.

The complete CVSS vector string was not included in the retrieved research note. The precise values for attack complexity, privileges required, user interaction, scope, and the confidentiality, integrity, and availability impact metrics therefore cannot be stated reliably. The available sources also do not specify the authentication requirement. The following facts are supported:

CVSS-related factor Assessment
Base score 9.9
Severity Critical
Remote exploitation Yes, according to the record
Attack complexity Not available
Privileges required Not available
User interaction Not available
Scope Not available
Confidentiality, integrity, availability impacts Not individually published in the supplied data

The missing vector does not reduce the operational priority. A remotely reachable command-injection flaw in an edge router should be handled as a high-risk exposure until the access-control requirements are confirmed. Obtain the authoritative vector from the NVD record or a vendor advisory before using individual CVSS components for prioritization or compliance reporting.

Exploitation Status

A public exploit reference exists. NVD states that “the exploit has been made available to the public and could be used for attacks” and links to a GitHub Gist attributed to H3rmesk1t:

https://gist.github.com/H3rmesk1t/c071a62375f38b629f67653428a8f25a

The available research confirms that the reference is public, but it does not independently validate the exploit’s reliability, authentication requirements, payload behavior, or compatibility with all N150RT deployments. Do not execute unreviewed exploit code against production equipment. If validation is required, use an isolated lab device with no route to production networks and preserve the original firmware and configuration for comparison.

CVE-2026-100896 is not listed in the CISA Known Exploited Vulnerabilities catalog as of the research date. No confirmed in-the-wild exploitation, ransomware campaign, CISA date-added entry, or remediation deadline was identified. That status means exploitation has not been confirmed through the KEV catalog; it does not demonstrate that attacks are absent. The combination of a 9.9 rating, remote command injection, and public exploit availability warrants urgent containment.

Analyst’s Take: The first control to verify is whether the Web Management Interface is reachable from the Internet, because the available sources do not establish the authentication or privilege requirements. KEV does not list the CVE, but the public exploit reference and lack of a vendor-confirmed fixed version still make exposure containment the practical priority.

Sources

The primary source is the NVD CVE record and API entry:

The public exploit reference cited by NVD is:

Additional references included with the vulnerability record are:

For exploitation-status verification, consult the CISA Known Exploited Vulnerabilities Catalog. The CVE was not listed there in the supplied research. No vendor-confirmed fixed version was identified, so defenders should verify any later TOTOLINK firmware directly with the vendor before treating it as a remediation.

This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.

ResponderRunbook · act now

Detection Guidance

Start with HTTP access logs from reverse proxies, upstream firewalls, WAN monitoring systems, and any centralized router logging available. Look for requests to the affected endpoint and suspicious values in the wlanif parameter. A useful initial search pattern is:

/boafrm/formWlSiteSurvey
wlanif=

For environments that export web requests to a SIEM, a generic query can identify likely probing:

http.request.uri.path = "/boafrm/formWlSiteSurvey"
AND http.request.uri.query contains "wlanif"

Exact field names vary by platform. Normalize URL-decoded and encoded query strings before matching. Alert on shell metacharacters, command separators, subshell syntax, or unexpected whitespace in the parameter, but do not assume that one pattern captures every payload. Examples of suspicious values include encoded separators or shell expressions. Public exploit code may change, so defenders should not rely on a fixed payload signature.

Monitor behavior after suspicious requests as well. Relevant indicators include unexpected outbound connections from the router, DNS-server changes, new administrator accounts, modified wireless settings, altered firewall rules, repeated reboots, configuration resets, and connections to unfamiliar external addresses. If the router exports process or system logs, review entries near the request timestamp for command failures, shell launches, segmentation faults, or unexpected service restarts.

Remediation Steps

No vendor-confirmed fixed firmware version was identified in the available sources. The affected version is 3.4.0-B20201030, and a specific upgrade target cannot be responsibly supplied without an official TOTOLINK release or advisory. Check TOTOLINK’s official support channel for an N150RT firmware release that explicitly addresses this issue. Do not treat an arbitrary newer build as fixed unless the vendor confirms it.

Until a confirmed fixed release is available, disable remote administration from the Internet and restrict the management interface to a trusted administration network. A Linux gateway or firewall in front of the router can enforce a temporary block similar to:

# Replace WAN_IF and ROUTER_MGMT_IP with site-specific values.
sudo nft add rule inet filter forward iifname "WAN_IF" ip daddr ROUTER_MGMT_IP tcp dport 80 drop
sudo nft add rule inet filter forward iifname "WAN_IF" ip daddr ROUTER_MGMT_IP tcp dport 443 drop

The exact control-plane ports may differ by deployment, and these rules must be integrated into the organization’s persistent firewall configuration. Where possible, permit administration only from a management VLAN or approved administrator addresses. If the router offers a configuration setting for remote Web Management, disable it and verify from an external network that the interface is no longer reachable.

If a vendor-confirmed fixed firmware becomes available, update through the documented TOTOLINK administration process or approved firmware-recovery procedure, after exporting configuration and recording the current version. Because no fixed version is identified here, do not claim that upgrading to a particular build resolves CVE-2026-100896. If the device cannot be patched, isolate it from the Internet, place it behind a supported security gateway, and schedule replacement. Unsupported equipment should not remain as an Internet-facing edge device.

If compromise is suspected, preserve logs and configuration evidence before resetting the router. Then disconnect or isolate the device, rotate administrative credentials and any secrets exposed through the router, restore known-good firmware where supported, and review DNS, firewall, wireless, and port-forwarding settings. A password manager such as Try 1Password → can help administrators generate and store unique replacement credentials during the recovery process.

Replacement is preferable when firmware integrity, persistence, or vendor support cannot be established.

Last verified: 2026-09-28

Disclaimer: This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.