PT-2026-72062 · Totolink · A800R

·

CVE-2026-19845

·

Published

2026-08-14

·

Updated

2026-08-14

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK A800R version 4.1.2cu.5137 B20200730
Description A stack-based buffer overflow exists in the lan.so component. The issue occurs within the setStaticDhcpConfig() function of the '/cgi-bin/cstecgi.cgi' endpoint. A remote attacker can trigger this by manipulating the Comment argument. A stack-based buffer overflow is a condition where a program writes more data to a buffer located on the stack than the buffer is allocated to hold, potentially leading to crashes or arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the '/cgi-bin/cstecgi.cgi' endpoint or avoid using the Comment argument within the setStaticDhcpConfig() function.

Exploit

Stack Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19845

Affected Products

A800R