CVE-2026-19812: TOTOLINK A800R product.so cstecgi.cgi UploadCustomModule stack-based overflow
A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation of the argument File causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19812?
CVE-2026-19812 has a high severity rating of 8.8.
How do I fix CVE-2026-19812?
To fix CVE-2026-19812, update the TOTOLINK A800R firmware to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-19812?
CVE-2026-19812 is categorized as a stack-based buffer overflow vulnerability.
What component is affected by CVE-2026-19812?
CVE-2026-19812 affects the UploadCustomModule function in the product.so component of the TOTOLINK A800R.
Can CVE-2026-19812 be exploited remotely?
Yes, CVE-2026-19812 can be exploited remotely due to the nature of the vulnerability.