Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Totolink n150rt
|
|
| Vendors & Products |
Totolink n150rt
|
Mon, 28 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. | |
| Title | TOTOLINK N150RT Web Management formWlSiteSurvey system os command injection | |
| First Time appeared |
Totolink
Totolink n150rt Firmware |
|
| Weaknesses | CWE-77 CWE-78 |
|
| CPEs | cpe:2.3:o:totolink:n150rt_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Totolink
Totolink n150rt Firmware |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-28T12:56:46.536Z
Reserved: 2026-09-27T08:32:34.128Z
Link: CVE-2026-100896
No data.
Status : Deferred
Published: 2026-09-28T02:17:19.617
Modified: 2026-09-28T15:16:04.793
Link: CVE-2026-100896
No data.
OpenCVE Enrichment
Updated: 2026-09-28T16:00:03Z