Description
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-08-14
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack‑based buffer overflow exists in the setIpQosRules function of the firewall.so component, triggered by an excessively long Comment argument in /cgi-bin/cstecgi.cgi. The flaw can be exploited remotely, allowing an attacker to overwrite the stack and execute arbitrary code on the device, compromising confidentiality, integrity, and availability of the network appliance. The weakness is classified as CWE‑119 and CWE‑121.

Affected Systems

The vulnerability affects TOTOLINK A800R routers running firmware version 4.1.2cu.5137_B20200730. Only this specific firmware build is known to be vulnerable; other revisions are not known to be impacted.

Risk and Exploitability

With a CVSS score of 8.7 the flaw is considered high severity. The EPSS score is not available, but the exploit has been released publicly and may be used for attacks. Although the vulnerability is not listed in CISA KEV, its remote exploitation capability and available exploit code indicate a significant risk of compromise in exposed or poorly secured environments.

Generated by OpenCVE AI on August 14, 2026 at 07:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device to the latest firmware released by TOTOLINK that includes a fix for the buffer overflow in firewall.so.
  • If an upgrade is not immediately available, block external access to /cgi-bin/cstecgi.cgi using firewall rules or disable the CGI script entirely through the device’s management interface.
  • Configure the router to allow remote management only from trusted IP addresses and enforce strong authentication, thereby reducing the attack surface for remote exploitation.

Generated by OpenCVE AI on August 14, 2026 at 07:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a800r
Vendors & Products Totolink a800r

Fri, 14 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Title TOTOLINK A800R firewall.so cstecgi.cgi setIpQosRules stack-based overflow
First Time appeared Totolink
Totolink a800r Firmware
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:o:totolink:a800r_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a800r Firmware
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A800r A800r Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-14T06:15:11.415Z

Reserved: 2026-08-14T00:55:34.923Z

Link: CVE-2026-19811

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T07:16:52.627

Modified: 2026-08-14T07:16:52.627

Link: CVE-2026-19811

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T07:30:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow