{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-100896/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:totolink:n150rt:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-100896"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["N150RT (3.4.0-B20201030)"],"_cs_severities":["critical"],"_cs_tags":["cve-2026-100896","command-injection","remote-code-execution","network-appliance"],"_cs_type":"threat","_cs_vendors":["TOTOLINK"],"content_html":"\u003cp\u003eTOTOLINK N150RT firmware version 3.4.0-B20201030 contains a critical command injection vulnerability (CVE-2026-100896) within its Web Management Interface. The flaw is located in the '/boafrm/formWlSiteSurvey' handler, which improperly sanitizes user-supplied input provided to the 'wlanif' argument. An unauthenticated remote attacker can leverage this vulnerability to inject and execute arbitrary system-level commands on the underlying device. Given that public exploit code is already available, the risk of active exploitation by threat actors is high. Defenders should ensure these devices are isolated from the public internet and monitored for suspicious HTTP POST requests directed at the identified handler.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify accessible TOTOLINK N150RT web management interfaces.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an HTTP POST request to the target device endpoint: /boafrm/formWlSiteSurvey.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious payload containing shell metacharacters (e.g., ;, |, \u0026amp;\u0026amp;) within the 'wlanif' parameter.\u003c/li\u003e\n\u003cli\u003eThe web server process parses the HTTP request and passes the tainted 'wlanif' argument to a system-level function call.\u003c/li\u003e\n\u003cli\u003eThe underlying OS executes the injected command with the privileges of the web management service.\u003c/li\u003e\n\u003cli\u003eThe attacker establishes a reverse shell or downloads secondary payloads to achieve persistent unauthorized access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full system compromise, including unauthorized code execution, potential exfiltration of sensitive configuration data, and the ability to repurpose the device for further malicious activities within the local network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately restrict access to the Web Management Interface of TOTOLINK devices from the public internet.\u003c/li\u003e\n\u003cli\u003eImplement network-level monitoring to detect POST requests to '/boafrm/formWlSiteSurvey' containing shell metacharacters in the query parameters.\u003c/li\u003e\n\u003cli\u003eUpdate firmware to the latest available version if a patch is provided by the manufacturer, as version 3.4.0-B20201030 is confirmed vulnerable.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-28T03:11:42Z","date_published":"2026-09-28T03:11:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-totolink-rce/","summary":"An OS command injection vulnerability in the TOTOLINK N150RT web interface allows unauthenticated remote attackers to execute arbitrary commands via the wlanif parameter.","title":"Remote Code Execution in TOTOLINK N150RT","url":"https://feed.craftedsignal.io/briefs/2026-09-totolink-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-100896","version":"https://jsonfeed.org/version/1.1"}