What is CVE-2026-19814?
A vulnerability in TOTOLINK A800R 4.1.2cu.5137_B20200730 allows stack-based buffer overflow via manipulation of the 'macAddress' argument in the 'setMacQos' function within '/cgi-bin/cstecgi.cgi'. Remote exploitation may lead to code execution, and updating the firmware along with restricting admin interface access is recommended.
Azərbaycanca: Bu TOTOLINK A800R 4.1.2cu.5137_B20200730 routerində aşkar edilmiş zəiflikdir. '/cgi-bin/cstecgi.cgi' faylındakı 'setMacQos' funksiyasında 'macAddress' parametrinin manipulyasiyası nəticəsində stack-based buffer overflow yaranır. İstismar uzaqdan kodu icra etməyə imkan verə bilər, cihazı son versiyaya yeniləmək və idarəetmə interfeysinə girişi məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: TOTOLINK
FAQ2
Which device and firmware version does CVE-2026-19814 affect?
This vulnerability affects TOTOLINK A800R router version 4.1.2cu.5137_B20200730.
What risk can arise from exploiting CVE-2026-19814?
Exploitation may lead to remote code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.