CVE-2026-19814
8.8TOTOLINK · A800R
A stack-based buffer overflow vulnerability in the TOTOLINK A800R router allows authenticated attackers to execute arbitrary code via the setMacQos function.
Executive summary
A critical stack-based buffer overflow vulnerability in the TOTOLINK A800R router allows authenticated attackers to achieve remote code execution, threatening network integrity.
Vulnerability
This is a memory corruption flaw (CWE-119, CWE-121) occurring in the setMacQos function, which can be triggered by a specially crafted request from an authenticated user.
Business impact
Successful exploitation allows an attacker to gain unauthorized control over the network device, potentially leading to unauthorized access to internal network traffic or complete service disruption. The CVSS score of 8.8 highlights the high risk posed to infrastructure stability and organizational security.
Remediation
Immediate Action: Apply the latest firmware security updates provided by TOTOLINK immediately to address this memory corruption flaw.
Proactive Monitoring: Monitor network device logs for crashes or unusual traffic patterns, especially those involving QoS configuration attempts, which may indicate exploitation efforts.
Compensating Controls: Restrict administrative access to the device management interface to trusted internal IP addresses only, reducing the attack surface for potentially malicious authenticated users.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The severity of this vulnerability necessitates immediate attention from network administrators. Ensure that all TOTOLINK A800R devices are updated to the latest firmware and that administrative access is strictly controlled to prevent exploitation of this buffer overflow.