CVE-2026-19813

8.8

TOTOLINK · A800R

A stack-based buffer overflow in the setMacFilterRules function of the TOTOLINK A800R router allows remote code execution via manipulation of the Comment argument.

Executive summary

A critical stack-based buffer overflow vulnerability in TOTOLINK A800R routers poses a significant risk of remote code execution for authenticated users.

Vulnerability

This is a stack-based buffer overflow vulnerability located in the setMacFilterRules function of the firewall.so component. It requires low-privileged authenticated access to the device to trigger via the Comment argument.

Business impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the affected router. Given the CVSS score of 8.8, this represents a high-severity threat that could lead to full system compromise, unauthorized network access, or the redirection of traffic. Such an event would severely impact business continuity and network integrity.

Remediation

Immediate Action: Contact the vendor for firmware updates, as no specific patch version is currently identified. If no update is available, restrict access to the management interface to trusted administrative subnets.

Proactive Monitoring: Monitor firewall and system access logs for anomalous traffic patterns or repeated attempts to access the cstecgi.cgi script.

Compensating Controls: Implement strict network segmentation and ensure that the administrative interface is not exposed to the public internet or untrusted internal segments.

Exploitation status

Public Exploit Available: Yes, a public exploit is available via the referenced GitHub repository.

Analyst recommendation

Due to the critical nature of this memory corruption vulnerability, administrators should prioritize restricting access to the device management interface immediately. Until the vendor provides a patched firmware version, isolating the affected hardware from critical network segments is the most effective way to prevent exploitation.

More TOTOLINK CVEs