CVE-2026-19814: TOTOLINK A800R firewall.so cstecgi.cgi setMacQos stack-based overflow
A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137B20200730. Affected is the function setMacQos of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Performing a manipulation of the argument macAddress results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19814?
CVE-2026-19814 has a severity rating of high with a score of 8.8.
What type of vulnerability is CVE-2026-19814?
CVE-2026-19814 is a stack-based buffer overflow vulnerability.
How do I fix CVE-2026-19814?
To fix CVE-2026-19814, it is recommended to update the firmware of the TOTOLINK A800R to the latest version provided by the manufacturer.
What component does CVE-2026-19814 affect?
CVE-2026-19814 affects the function setMacQos in the file /cgi-bin/cstecgi.cgi of the firewall.so component.
What can attackers achieve with CVE-2026-19814?
Attackers can exploit CVE-2026-19814 to perform arbitrary code execution due to the stack-based buffer overflow.