CVE-2026-7719: Totolink WA300 POST Request cstecgi.cgi loginauth buffer overflow
A security flaw has been discovered in Totolink WA300 5.2cu.7112B20190227. The affected element is the function loginauth of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument httphost results in buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7719?
CVE-2026-7719 is classified as a high-severity vulnerability due to the potential for remote code execution caused by a buffer overflow.
How do I fix CVE-2026-7719?
To fix CVE-2026-7719, update the Totolink WA300 to the latest firmware version that addresses this vulnerability.
What type of vulnerability is CVE-2026-7719?
CVE-2026-7719 is a buffer overflow vulnerability occurring in the loginauth function within the cstecgi.cgi script.
Which devices are affected by CVE-2026-7719?
CVE-2026-7719 affects the Totolink WA300 running firmware version 5.2cu.7112_B20190227.
What could be the consequences of exploiting CVE-2026-7719?
Exploiting CVE-2026-7719 could allow an attacker to execute arbitrary code on the affected device, potentially compromising the router and its network.