---
id: CVE-2026-94953
title: >-
  A stack-based buffer overflow vulnerability exists in the web management
  interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030
summary: >-
  A stack-based buffer overflow vulnerability exists in the web management
  interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is
  reachable through the route /boafrm/formAjaxSet using the
  topicurl=setting/setWiFiRepeaterCon…
severity: none
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T21:28:02.477'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94953'
references:
  - url: 'https://gist.github.com/H3rmesk1t/039c2c968fd535cfffecdf9626e963e2'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T19:44:04.163Z'
---

## Overview

A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formAjaxSet using the topicurl=setting/setWiFiRepeaterConfig branch and the ApCliWEPKey field.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
