What is CVE-2026-19815?
A critical flaw in TOTOLINK A800R router's setParentalRules function within the firewall.so component allows a stack-based buffer overflow via the urlKeyword parameter. This can lead to remote code execution, and since the vendor likely no longer supports this model, the device should be isolated from the network immediately.
Azərbaycanca: Bu kritik boşluq TOTOLINK A800R router-in firewall.so komponentindəki setParentalRules funksiyasında aşkarlanıb. urlKeyword arqumenti üzərində manipulyasiya stack-based buffer overflow yaradır və uzaqdan kod icrasına səbəb ola bilər. İstehsalçı tərəfindən rəsmi yamaq təqdim edilmədiyi üçün bu modelin istifadəsi dayandırılmalı və ya şəbəkədən təcrid edilməlidir.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: TOTOLINK
FAQ2
Which TOTOLINK router model is affected by CVE-2026-19815?
This critical vulnerability has been discovered in the TOTOLINK A800R router model.
What can an attacker achieve by exploiting CVE-2026-19815?
An attacker can manipulate the urlKeyword argument to trigger a stack-based buffer overflow, leading to remote code execution (RCE).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.