CVE-2026-19844
8.8TOTOLINK · A800R
A stack-based buffer overflow in the TOTOLINK A800R web interface allows remote attackers to execute arbitrary code via the setRadvdCfg function.
Executive summary
A critical stack-based buffer overflow in the TOTOLINK A800R router allows authenticated attackers to gain control over device memory and execute arbitrary commands.
Vulnerability
This vulnerability involves a stack-based buffer overflow (CWE-121) in the setRadvdCfg function within the ipv6.so component. By sending a crafted request to the web interface, a user with low privileges can manipulate the radvdinterfacename argument to trigger memory corruption.
Business impact
With a CVSS score of 8.8, this vulnerability represents a significant threat to organizational network integrity. An attacker who successfully exploits this flaw can achieve arbitrary code execution, which could result in the total compromise of the router, leading to unauthorized data access or disruption of network services.
Remediation
Immediate Action: Monitor official vendor communication for a firmware patch to address this memory corruption and apply it immediately upon release.
Proactive Monitoring: Monitor network and device logs for suspicious POST requests targeted at the IPv6 configuration settings of the router.
Compensating Controls: Restrict management interface access to authorized personnel only and disable unnecessary IPv6 services if they are not required for current operations.
Exploitation status
Public Exploit Available: Yes, a public exploit is currently available.
Analyst recommendation
The combination of a high CVSS score and existing public exploit code indicates that this vulnerability is highly dangerous. Organizations should move to isolate the affected devices from external networks until a vendor-supplied patch is successfully deployed.