PT-2026-72063 · Totolink · A800R

·

CVE-2026-19846

·

Published

2026-08-14

·

Updated

2026-08-14

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK A800R version 4.1.2cu.5137 B20200730
Description A remote attack is possible due to a stack-based buffer overflow in the firewall.so component. The issue occurs within the setUrlFilterRules() function of the '/cgi-bin/cstecgi.cgi' endpoint when the url argument is manipulated. A stack-based buffer overflow is a condition where a program writes more data to a buffer located on the stack than the buffer is allocated to hold, potentially leading to crashes or arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the '/cgi-bin/cstecgi.cgi' endpoint or avoid using the url parameter within the setUrlFilterRules() function.

Exploit

Stack Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19846

Affected Products

A800R