CVE-2026-19815

8.8

TOTOLINK · A800R

A stack-based buffer overflow vulnerability in the TOTOLINK A800R router allows authenticated attackers to execute arbitrary code via the setParentalRules function.

Executive summary

A critical stack-based buffer overflow vulnerability in the TOTOLINK A800R router allows authenticated attackers to execute arbitrary code, compromising the security of the device.

Vulnerability

This vulnerability involves a stack-based buffer overflow (CWE-121) within the setParentalRules function, which is susceptible to memory corruption (CWE-119) when processing input from an authenticated user.

Business impact

Exploitation of this vulnerability allows an attacker to execute arbitrary code on the device, potentially leading to full control over network routing and filtering. With a CVSS score of 8.8, the risk of unauthorized access and potential data interception is high, necessitating urgent remediation.

Remediation

Immediate Action: Update the firmware of all affected TOTOLINK A800R units to the latest version provided by the manufacturer to mitigate this memory corruption vulnerability.

Proactive Monitoring: Monitor system logs for unexpected device reboots or errors associated with parental control rule updates, which could indicate a failed or successful exploit attempt.

Compensating Controls: Limit access to the administrative console and configuration features to authorized personnel and trusted management subnets to prevent unauthorized exploitation.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for remote code execution, it is critical to address this vulnerability by applying the vendor-issued firmware patch. Security teams should prioritize this update to ensure the integrity of the network infrastructure and protect against unauthorized device control.

More TOTOLINK CVEs