CVE-2026-19847: TOTOLINK A800R wps.so cstecgi.cgi setWiFiWpsConfig stack-based overflow
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation of the argument pin results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19847?
The severity of CVE-2026-19847 is classified as high with a score of 8.8.
How do I fix CVE-2026-19847?
To fix CVE-2026-19847, update the TOTOLINK A800R firmware to the latest version provided by the manufacturer.
Which component is affected in CVE-2026-19847?
CVE-2026-19847 affects the setWiFiWpsConfig function in the /cgi-bin/cstecgi.cgi component of the wps.so.
Can CVE-2026-19847 be exploited remotely?
Yes, CVE-2026-19847 can be exploited remotely due to its stack-based buffer overflow vulnerability.
What type of vulnerability is CVE-2026-19847 classified as?
CVE-2026-19847 is classified as a Buffer Overflow vulnerability.