TOTOLINK vulnerabilities
11 CVEs tracked
TOTOLINK's A800R model (firmware version 4.1.2cu.5137_B20200730) has been reported with multiple, simultaneous stack-based buffer overflow vulnerabilities. All flaws are concentrated in the `/cgi-bin/cstecgi.cgi` file, impacting various components such as firewall.so, product.so, lan.so, ipv6.so, and wps.so. These critical vulnerabilities, tracked as CVE-2026-19811, CVE-2026-19812, CVE-2026-19813, CVE-2026-19814, CVE-2026-19815, CVE-2026-19844, CVE-2026-19845, and CVE-2026-19847, can potentially allow unauthenticated remote code execution (RCE). Defenders should immediately treat this model as end-of-life, isolate it from critical networks, and enforce strict access control policies for any remaining devices on the network perimeter.
Azərbaycanca: TOTOLINK-in A800R modeli (4.1.2cu.5137_B20200730 proqram təminatı) üzrə hesabatlarda eyni vaxtda bir neçə stack-based buffer overflow zəifliyi aşkarlanıb. Bütün zəifliklər `/cgi-bin/cstecgi.cgi` faylındakı funksiyalarla bağlıdır və müxtəlif komponentləri (firewall.so, product.so, lan.so, ipv6.so, wps.so) əhatə edir. Bu kritik qüsurlar, xüsusilə CVE-2026-19811, CVE-2026-19812, CVE-2026-19813, CVE-2026-19814, CVE-2026-19815, CVE-2026-19844, CVE-2026-19845 və CVE-2026-19847 kimi identifikatorlarla izlənir, autentifikasiya olunmadan uzaqdan kod icrasına (RCE) səbəb ola bilər. Müdafiəçi dərhal bu modelin istismar müddətinin bitdiyini (end-of-life) qəbul etməli, şəbəkədən təcrid etməli və ya kritik şəbəkə perimetrində olan bu cihazlar üçün giriş nəzarəti siyasətlərini sərtləşdirməlidir.
This vendor's CVEs11
This hub is built from skopnix's own reporting on TOTOLINK: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.