What is CVE-2026-19813?
A stack-based buffer overflow vulnerability was identified in the setMacFilterRules function of TOTOLINK A800R firmware version 4.1.2cu.5137_B20200730. This flaw, located in /cgi-bin/cstecgi.cgi within the firewall.so component, can be exploited via the Comment argument. Affected devices should be updated immediately to prevent potential remote code execution.
Azərbaycanca: TOTOLINK A800R routerinin 4.1.2cu.5137_B20200730 versiyasında, firewall.so komponentinin /cgi-bin/cstecgi.cgi faylındakı setMacFilterRules funksiyasında stack-based buffer overflow zəifliyi aşkarlanıb. Bu, Comment arqumentinin manipulyasiyası ilə uzaqdan kod icrasına səbəb ola bilər. Təsirlənmiş cihazları mümkün qədər tez yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: TOTOLINK
FAQ2
Which firmware version of the TOTOLINK A800R router is affected by CVE-2026-19813?
It affects firmware version 4.1.2cu.5137_B20200730 of the TOTOLINK A800R router.
What can an attacker achieve by exploiting CVE-2026-19813?
This vulnerability can lead to remote code execution (RCE) via the Comment argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.