CVE-2026-19811: TOTOLINK A800R firewall.so cstecgi.cgi setIpQosRules stack-based overflow
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19811?
CVE-2026-19811 has a severity score of 8.8 on the CVSS scale, indicating a high risk.
How do I fix CVE-2026-19811?
To fix CVE-2026-19811, update to the latest version of the TOTOLINK A800R firmware that addresses this vulnerability.
What type of vulnerability is CVE-2026-19811?
CVE-2026-19811 is a stack-based buffer overflow vulnerability found in the setIpQosRules function.
What software is affected by CVE-2026-19811?
The TOTOLINK A800R router running firmware version 4.1.2cu.5137_B20200730 is affected by CVE-2026-19811.
What impact does CVE-2026-19811 have on security?
CVE-2026-19811 allows an attacker to execute arbitrary code due to a stack-based overflow, which can compromise the device.