What is CVE-2026-19847?
CVE-2026-19847 is a critical stack-based buffer overflow vulnerability in the TOTOLINK A800R router. The flaw exists in the `setWiFiWpsConfig` function within `/cgi-bin/cstecgi.cgi` when handling the `pin` argument, allowing for remote code execution. Users should immediately apply firmware updates from the vendor or disconnect affected devices from the network.
Azərbaycanca: CVE-2026-19847 TOTOLINK A800R marşrutlaşdırıcısında aşkar edilmiş kritik boşluqdur. /cgi-bin/cstecgi.cgi faylındakı setWiFiWpsConfig funksiyasında `pin` arqumentinin manipulyasiyası nəticəsində stack-based buffer overflow yaranır, bu da uzaqdan kod icrasına şərait yarada bilər. Təsirlənən cihaz sahibləri dərhal istehsalçıdan firmware yeniləməsini tətbiq etməli və ya mümkündürsə, cihazı şəbəkədən ayırmalıdır.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: TOTOLINK
FAQ2
In which function within the TOTOLINK A800R was CVE-2026-19847 discovered?
CVE-2026-19847 was discovered in the `setWiFiWpsConfig` function within `/cgi-bin/cstecgi.cgi`.
Manipulation of which argument leads to CVE-2026-19847?
CVE-2026-19847 is triggered by manipulation of the `pin` argument, causing a stack-based buffer overflow.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.