CVE-2026-19811
8.8TOTOLINK · A800R
A stack-based buffer overflow in the setIpQosRules function of the TOTOLINK A800R router allows remote code execution via manipulation of the Comment argument.
Executive summary
A critical buffer overflow in TOTOLINK A800R routers creates a pathway for remote code execution, necessitating urgent mitigation steps to protect network infrastructure.
Vulnerability
This is a stack-based buffer overflow vulnerability occurring in the setIpQosRules function of the firewall.so component. An authenticated attacker can trigger this remotely by providing a malicious Comment argument.
Business impact
The CVSS score of 8.8 underscores the critical nature of this flaw. Successful exploitation allows an attacker to achieve remote code execution, which may lead to the total loss of confidentiality, integrity, and availability of the affected device and potentially the connected local network.
Remediation
Immediate Action: Monitor vendor communications for a security patch. Until a patch is released, ensure the management interface is inaccessible to non-administrative users.
Proactive Monitoring: Monitor device logs for errors or crashes associated with the firewall.so component or unusual inputs provided to the QoS configuration settings.
Compensating Controls: Restrict access to the device's web management interface to a dedicated management VLAN or VPN to minimize the attack surface.
Exploitation status
Public Exploit Available: Yes, a public exploit is available via the referenced GitHub repository.
Analyst recommendation
Given the availability of a public exploit, this vulnerability poses an immediate threat to the operational stability of the TOTOLINK A800R. Security teams should prioritize limiting exposure of the device's management interface and apply any vendor-supplied security updates immediately upon release.