CVE-2026-100896 PUBLISHED

TOTOLINK N150RT Web Management formWlSiteSurvey system os command injection

Assigner: VulDB
Reserved: 27.09.2026 Published: 28.09.2026 Updated: 28.09.2026

A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
CVSS Score: 9.4

Product Status

Vendor TOTOLINK
Product N150RT
Versions
  • Version 3.4.0-B20201030 is affected

Credits

  • H3rmesk1t (VulDB User) reporter

References

Problem Types

  • OS Command Injection CWE
  • Command Injection CWE