What is CVE-2026-19845?
A stack-based buffer overflow vulnerability exists in the setStaticDhcpConfig function within the /cgi-bin/cstecgi.cgi file of TOTOLINK A800R firmware version 4.1.2cu.5137_B20200730, triggered by manipulating the Comment argument. This could allow remote code execution on the affected device. Access to the device's management interface should be restricted until a vendor-supplied patch is available.
Azərbaycanca: TOTOLINK A800R routerinin 4.1.2cu.5137_B20200730 versiyasında /cgi-bin/cstecgi.cgi faylındakı setStaticDhcpConfig funksiyasında, Comment arqumentinin manipulyasiyası nəticəsində stack-based buffer overflow zəifliyi aşkar edilib. Bu, cihazın uzaqdan idarə olunmasına səbəb ola bilər. İstehsalçı tərəfindən yamaq təqdim olunana qədər cihazın idarəetmə interfeysinə giriş məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: TOTOLINK
FAQ2
Which TOTOLINK router model and firmware version are affected by CVE-2026-19845?
This vulnerability affects the TOTOLINK A800R router running firmware version 4.1.2cu.5137_B20200730.
What temporary measure should be taken for CVE-2026-19845 until a vendor patch is available?
Access to the device's management interface should be restricted.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.