What is CVE-2026-19846?
CVE-2026-19846 is a critical vulnerability in TOTOLINK A800R version 4.1.2cu.5137_B20200730, where the setUrlFilterRules function in /cgi-bin/cstecgi.cgi mishandles the 'url' argument, leading to a stack-based buffer overflow. This allows remote attackers to execute arbitrary code. Disconnect the affected device immediately and await a patch from the vendor.
Azərbaycanca: CVE-2026-19846, TOTOLINK A800R marşrutlaşdırıcısının 4.1.2cu.5137_B20200730 versiyasında aşkar edilmiş kritik boşluqdur. /cgi-bin/cstecgi.cgi faylındakı setUrlFilterRules funksiyasında 'url' arqumentinin işlənməsi stack-based buffer overflow yaradaraq uzaqdan kod icrasına imkan verir. Cihazı dərhal şəbəkədən ayırıb istehsalçıdan yamaq gözləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: TOTOLINK
FAQ2
Which TOTOLINK A800R versions are affected by CVE-2026-19846?
Only version 4.1.2cu.5137_B20200730 is affected.
What is the recommendation for a device affected by CVE-2026-19846?
The recommendation is to disconnect the device from the network immediately and await a patch from the vendor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.