{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-100896","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-09-27T08:32:34.128Z","datePublished":"2026-09-28T01:30:14.267Z","dateUpdated":"2026-09-28T12:56:46.536Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-09-28T01:30:14.267Z"},"title":"TOTOLINK N150RT Web Management formWlSiteSurvey system os command injection","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-78","lang":"en","description":"OS Command Injection"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-77","lang":"en","description":"Command Injection"}]}],"affected":[{"vendor":"TOTOLINK","product":"N150RT","versions":[{"version":"3.4.0-B20201030","status":"affected"}],"cpes":["cpe:2.3:o:totolink:n150rt_firmware:*:*:*:*:*:*:*:*"],"modules":["Web Management Interface"]}],"descriptions":[{"lang":"en","value":"A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":9.4,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P","baseSeverity":"CRITICAL"}},{"cvssV3_1":{"version":"3.1","baseScore":9.9,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R","baseSeverity":"CRITICAL"}},{"cvssV3_0":{"version":"3.0","baseScore":9.9,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R","baseSeverity":"CRITICAL"}},{"cvssV2_0":{"version":"2.0","baseScore":9,"vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"}}],"timeline":[{"time":"2026-09-27T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-09-27T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-09-27T10:37:39.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"H3rmesk1t (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/vuln/410846","name":"VDB-410846 | TOTOLINK N150RT Web Management formWlSiteSurvey system os command injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/410846/cti","name":"VDB-410846 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-100896","name":"CVE-2026-100896 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/918574","name":"Submit #918574 | TOTOLINK N150RT V3.4.0-B20201030 Command Injection","tags":["third-party-advisory"]},{"url":"https://gist.github.com/H3rmesk1t/c071a62375f38b629f67653428a8f25a","tags":["exploit"]},{"url":"https://www.totolink.net/","tags":["product"]}],"x_generator":["VulDB PVTS v202609"]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-28T12:56:35.313082Z","id":"CVE-2026-100896","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-28T12:56:46.536Z"}}]}}