CVE-2026-19847

8.8

TOTOLINK · A800R

A stack-based buffer overflow in the TOTOLINK A800R web interface allows remote attackers to achieve arbitrary code execution via the setWiFiWpsConfig function.

Executive summary

A critical stack-based buffer overflow in the TOTOLINK A800R router poses a severe risk of remote code execution for authenticated users.

Vulnerability

This vulnerability is a stack-based buffer overflow (CWE-121) located in the setWiFiWpsConfig function of the wps.so component. An attacker with low-level access can trigger this memory corruption by manipulating the pin argument within the device web interface.

Business impact

The CVSS score of 8.8 reflects the high potential for system compromise. Successful exploitation allows an attacker to execute arbitrary code with elevated privileges, potentially leading to full device takeover, interception of network traffic, or use of the router as a pivot point for further lateral movement within the internal network.

Remediation

Immediate Action: Since no specific patch version is currently available, contact the vendor for emergency firmware updates or disable the vulnerable Wi-Fi Protected Setup (WPS) feature if possible.

Proactive Monitoring: Review device access logs for unusual administrative activity or repeated attempts to access the WPS configuration endpoints.

Compensating Controls: Implement a Web Application Firewall or restrict access to the web management interface to trusted administrative IP addresses only to reduce the attack surface.

Exploitation status

Public Exploit Available: Yes, a public exploit has been identified via GitHub.

Analyst recommendation

Given the critical severity and the availability of public exploit code, administrators must prioritize hardening these devices. If a firmware update from the vendor becomes available, it should be deployed immediately to address the underlying memory corruption flaw.

More TOTOLINK CVEs