What is CVE-2026-19844?
A stack-based buffer overflow vulnerability was identified in the setRadvdCfg function located in /cgi-bin/cstecgi.cgi of the ipv6.so component on TOTOLINK A800R firmware version 4.1.2cu.5137_B20200730, triggered by manipulating the radvdinterfacename argument. This could allow remote code execution. Users are advised to temporarily disable the device until a vendor patch is released.
Azərbaycanca: TOTOLINK A800R 4.1.2cu.5137_B20200730 routerin /cgi-bin/cstecgi.cgi faylında yerləşən setRadvdCfg funksiyasında ipv6.so komponenti vasitəsilə radvdinterfacename arqumenti işlənərkən stack-based buffer overflow zəifliyi aşkar edilib. Bu zəiflik uzaqdan kod icrasına imkan yarada bilər. İstifadəçilərə istehsalçı tərəfindən yeniləmə buraxılana qədər cihazı müvəqqəti söndürmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: TOTOLINK
FAQ2
In which component of the TOTOLINK A800R router was CVE-2026-19844 found?
This vulnerability was found in the setRadvdCfg function of the ipv6.so component on TOTOLINK A800R router version 4.1.2cu.5137_B20200730.
What can an attacker achieve by exploiting CVE-2026-19844?
By manipulating the radvdinterfacename argument, an attacker can trigger a stack-based buffer overflow and achieve remote code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.