CVE-2026-19844: TOTOLINK A800R ipv6.so cstecgi.cgi setRadvdCfg stack-based overflow
A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component ipv6.so. Performing a manipulation of the argument radvdinterfacename results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19844?
CVE-2026-19844 has a high severity score of 8.8.
How do I fix CVE-2026-19844?
To fix CVE-2026-19844, update the TOTOLINK A800R device to the latest firmware version that addresses the vulnerability.
What type of vulnerability is CVE-2026-19844?
CVE-2026-19844 is classified as a stack-based buffer overflow vulnerability.
What component is affected by CVE-2026-19844?
The vulnerability affects the function setRadvdCfg in the file /cgi-bin/cstecgi.cgi of the ipv6.so component.
What could happen if CVE-2026-19844 is exploited?
Exploitation of CVE-2026-19844 could allow an attacker to execute arbitrary code on the affected device.