CVE-2026-19845

8.8

TOTOLINK · A800R

A stack-based buffer overflow vulnerability exists in TOTOLINK A800R that allows an authenticated attacker to trigger memory corruption.

Executive summary

A stack-based buffer overflow in the TOTOLINK A800R router poses a significant risk of arbitrary code execution for authenticated attackers.

Vulnerability

This vulnerability is caused by a stack-based buffer overflow (CWE-121) and memory corruption (CWE-119) within the device firmware. Successful exploitation requires the attacker to have low-level authenticated access to the device management interface.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting the potential for total compromise of the device's confidentiality, integrity, and availability. Successful exploitation could allow an attacker to gain unauthorized control over the network gateway, potentially facilitating lateral movement, traffic interception, or complete denial of service for the affected network segment.

Remediation

Immediate Action: Contact the vendor to obtain the latest firmware update for the A800R model and apply it immediately to resolve the memory corruption flaw.

Proactive Monitoring: Monitor network traffic for unusual management interface activity and review system logs for signs of unauthorized access or sudden device reboots.

Compensating Controls: Restrict access to the device management interface to trusted administrative IP addresses and disable remote management features if they are not required for business operations.

Exploitation status

Public Exploit Available: No (no confirmed weaponized exploit or public PoC repository identified).

Analyst recommendation

Given the high CVSS score and the presence of documented proof-of-concept research, administrators must prioritize the securing of these devices. If a vendor-supplied patch is unavailable, immediately isolate the affected hardware from untrusted network segments to prevent potential exploitation.

More TOTOLINK CVEs