CVE-2026-19845: TOTOLINK A800R lan.so cstecgi.cgi setStaticDhcpConfig stack-based overflow
A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TOTOLINK A800Rto a version that resolves this vulnerability.Fixed in 4.1.2cu.5137_B20200730 - Compensating control
Apply a compensating control by blocking remote access to the affected CGI handler /cgi-bin/cstecgi.cgi (component lan.so) at the network layer (e.g., firewall/ACL) to prevent remote exploitation of the stack-based buffer overflow in function setStaticDhcpConfig.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19845?
The severity of CVE-2026-19845 is rated high with a score of 8.8.
How do I fix CVE-2026-19845?
To fix CVE-2026-19845, it is recommended to update the TOTOLINK A800R firmware to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-19845?
CVE-2026-19845 is a stack-based buffer overflow vulnerability.
What component is affected by CVE-2026-19845?
CVE-2026-19845 affects the function setStaticDhcpConfig in the file /cgi-bin/cstecgi.cgi of the component lan.so.
What are the potential consequences of CVE-2026-19845?
Exploitation of CVE-2026-19845 may allow an attacker to execute arbitrary code on the affected device.