<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:totolink:n150rt:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3atotolinkn150rt/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 03:11:42 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3atotolinkn150rt/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution in TOTOLINK N150RT</title><link>https://feed.craftedsignal.io/briefs/2026-09-totolink-rce/</link><pubDate>Mon, 28 Sep 2026 03:11:42 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-totolink-rce/</guid><description>An OS command injection vulnerability in the TOTOLINK N150RT web interface allows unauthenticated remote attackers to execute arbitrary commands via the wlanif parameter.</description><content:encoded><![CDATA[<p>TOTOLINK N150RT firmware version 3.4.0-B20201030 contains a critical command injection vulnerability (CVE-2026-100896) within its Web Management Interface. The flaw is located in the '/boafrm/formWlSiteSurvey' handler, which improperly sanitizes user-supplied input provided to the 'wlanif' argument. An unauthenticated remote attacker can leverage this vulnerability to inject and execute arbitrary system-level commands on the underlying device. Given that public exploit code is already available, the risk of active exploitation by threat actors is high. Defenders should ensure these devices are isolated from the public internet and monitored for suspicious HTTP POST requests directed at the identified handler.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs network reconnaissance to identify accessible TOTOLINK N150RT web management interfaces.</li>
<li>Attacker initiates an HTTP POST request to the target device endpoint: /boafrm/formWlSiteSurvey.</li>
<li>Attacker crafts a malicious payload containing shell metacharacters (e.g., ;, |, &amp;&amp;) within the 'wlanif' parameter.</li>
<li>The web server process parses the HTTP request and passes the tainted 'wlanif' argument to a system-level function call.</li>
<li>The underlying OS executes the injected command with the privileges of the web management service.</li>
<li>The attacker establishes a reverse shell or downloads secondary payloads to achieve persistent unauthorized access.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for full system compromise, including unauthorized code execution, potential exfiltration of sensitive configuration data, and the ability to repurpose the device for further malicious activities within the local network.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Immediately restrict access to the Web Management Interface of TOTOLINK devices from the public internet.</li>
<li>Implement network-level monitoring to detect POST requests to '/boafrm/formWlSiteSurvey' containing shell metacharacters in the query parameters.</li>
<li>Update firmware to the latest available version if a patch is provided by the manufacturer, as version 3.4.0-B20201030 is confirmed vulnerable.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>cve-2026-100896</category><category>command-injection</category><category>remote-code-execution</category><category>network-appliance</category></item></channel></rss>