CVE-2026-19846

8.8

TOTOLINK · A800R

A stack-based buffer overflow vulnerability in the TOTOLINK A800R router allows authenticated attackers to trigger memory corruption via the setUrlFilterRules function.

Executive summary

A high-severity memory corruption vulnerability in the TOTOLINK A800R router may allow authenticated attackers to disrupt system operations.

Vulnerability

This vulnerability involves a stack-based buffer overflow in the setUrlFilterRules function, requiring the attacker to have low-level privileges to initiate the attack.

Business impact

The CVSS score of 8.8 reflects the potential for total loss of system availability or unauthorized control. If exploited, an attacker could crash the routing service or execute arbitrary commands, leading to severe network disruption or unauthorized administrative access to the router hardware.

Remediation

Immediate Action: Verify the existence of a firmware update from the vendor and apply it immediately to address the underlying memory corruption flaw.

Proactive Monitoring: Review system logs for unexpected behavior related to URL filtering configurations or administrative configuration changes.

Compensating Controls: Use firewall rules to limit access to the router web management interface to authorized personnel only.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the existence of a proof-of-concept, the risk to the TOTOLINK A800R is credible. Organizations should prioritize updating the firmware to the latest secure version and ensure that administrative access to the device is strictly controlled and audited.

More TOTOLINK CVEs