What is CVE-2026-19812?
A stack-based buffer overflow vulnerability has been identified in the `UploadCustomModule` function within the `/cgi-bin/cstecgi.cgi` file of the `product.so` component in TOTOLINK A800R version 4.1.2cu.5137_B20200730. This flaw, triggered by manipulating the `File` argument, could allow a remote attacker to potentially execute arbitrary code on the affected device. Users are advised to update the router firmware to the latest available version.
Azərbaycanca: TOTOLINK A800R routerinin 4.1.2cu.5137_B20200730 versiyasında `product.so` komponentinin `/cgi-bin/cstecgi.cgi` faylında `UploadCustomModule` funksiyasında `File` arqumenti ilə bağlı stack-based buffer overflow zəifliyi aşkarlanıb. Bu, uzaqdan hücum edən şəxsə təsirə məruz qalmış cihazda potensial olaraq özbaşına kod icrasına imkan verə bilər. Router proqram təminatının ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: TOTOLINK
FAQ2
Which firmware version of my TOTOLINK A800R router is affected by the CVE-2026-19812 vulnerability?
The CVE-2026-19812 vulnerability has been specifically identified in version 4.1.2cu.5137_B20200730 of the TOTOLINK A800R router firmware.
What can a remote attacker achieve by exploiting this vulnerability?
A remote attacker who successfully exploits the CVE-2026-19812 stack-based buffer overflow vulnerability could potentially execute arbitrary code on the affected device.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.