Description
A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation of the argument File causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-08-14
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack-based buffer overflow exists in the UploadCustomModule function of /cgi-bin/cstecgi.cgi within the product.so component of TOTOLINK A800R firmware 4.1.2cu.5137_B20200730. By manipulating the File argument, an attacker can overwrite stack data and potentially hijack execution flow, allowing arbitrary code execution, and compromising confidentiality, integrity, and availability of the device.

Affected Systems

The vulnerability affects TOTOLINK A800R routers running firmware version 4.1.2cu.5137_B20200730. The product is the product.so library bundled in the router’s firmware.

Risk and Exploitability

The CVSS score of 8.7 classifies this flaw as high severity. The EPSS score is not available, yet the vulnerability has an openly published exploit, indicating that exploitation is feasible. The attack can be launched remotely by sending crafted requests to the /cgi-bin/cstecgi.cgi endpoint. Although the vulnerability is not yet listed in the CISA KEV catalog, the presence of a public exploit and the ease of remote access raise the likelihood that attackers may target vulnerable devices within close network proximity.

Generated by OpenCVE AI on August 14, 2026 at 08:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the TOTOLINK A800R firmware to a version where the UploadCustomModule flaw is fixed or remove the vulnerable feature from the device.
  • If a patch is unavailable, disable remote management or block access to /cgi-bin/cstecgi.cgi via firewall rules to prevent attackers from reaching the vulnerable endpoint.
  • Apply network segmentation and restrict which hosts can reach the router, limiting exposure to trusted internal networks.
  • Monitor device logs for abnormal requests to /cgi-bin/cstecgi.cgi and configure alerts for potential exploitation attempts.

Generated by OpenCVE AI on August 14, 2026 at 08:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a800r
Vendors & Products Totolink a800r

Fri, 14 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation of the argument File causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Title TOTOLINK A800R product.so cstecgi.cgi UploadCustomModule stack-based overflow
First Time appeared Totolink
Totolink a800r Firmware
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:o:totolink:a800r_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a800r Firmware
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A800r A800r Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-14T14:54:28.616Z

Reserved: 2026-08-14T00:55:39.511Z

Link: CVE-2026-19812

cve-icon Vulnrichment

Updated: 2026-08-14T14:54:21.251Z

cve-icon NVD

Status : Deferred

Published: 2026-08-14T08:17:38.263

Modified: 2026-08-14T19:09:56.813

Link: CVE-2026-19812

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T09:00:10Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow