What is CVE-2026-19811?
A stack-based buffer overflow vulnerability exists in the setIpQosRules function of TOTOLINK A800R 4.1.2cu.5137_B20200730 router, triggered by manipulating the `Comment` argument. This could allow remote code execution. Updating the router firmware is recommended.
Azərbaycanca: TOTOLINK A800R 4.1.2cu.5137_B20200730 routerində firewall.so komponentində yerləşən setIpQosRules funksiyası vasitəsilə `Comment` arqumentinin manipulyasiyası stack-based buffer overflow zəifliyinə səbəb olur. Bu, uzaqdan kod icrasına yol aça bilər. Router proqram təminatını yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: TOTOLINK
FAQ2
In which function of the TOTOLINK A800R router does CVE-2026-19811 exist?
This vulnerability exists in the setIpQosRules function within the router's firewall.so component.
Can CVE-2026-19811 lead to remote code execution?
Yes, manipulating the `Comment` argument triggers a stack-based buffer overflow, which could allow remote code execution (RCE).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.