CVE-2026-19815: TOTOLINK A800R firewall.so cstecgi.cgi setParentalRules stack-based overflow
A flaw has been found in TOTOLINK A800R 4.1.2cu.5137B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Executing a manipulation of the argument urlKeyword can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19815?
The severity of CVE-2026-19815 is rated as high with a score of 8.8.
How do I fix CVE-2026-19815?
To fix CVE-2026-19815, update the TOTOLINK A800R firmware to the latest version provided by the vendor.
What is the impact of CVE-2026-19815 on the system?
CVE-2026-19815 can lead to a stack-based buffer overflow, allowing an attacker to execute arbitrary code.
Which component is affected by CVE-2026-19815?
CVE-2026-19815 affects the function setParentalRules in the file /cgi-bin/cstecgi.cgi of the component firewall.so.
Is CVE-2026-19815 remote exploit capable?
Yes, CVE-2026-19815 can be exploited remotely due to its high attack vector.