Description
A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Published: 2026-08-14
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack‑based buffer overflow exists in the setMacFilterRules function of /cgi-bin/cstecgi.cgi on the TOTOLINK A800R. The vulnerability is triggered by manipulating the Comment argument, causing a stack corruption that can lead to arbitrary code execution. The weakness is classified as CWE-119 and CWE-121.

Affected Systems

The affected product is the TOTOLINK A800R model with firmware version 4.1.2cu.5137_B20200730. The vulnerability lies in the firewall.so component and the setMacFilterRules endpoint exposed via the web interface.

Risk and Exploitability

The CVSS score is 8.7, indicating high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The description states that the attack can be performed from remote, and a public exploit has already been disclosed. This combination of remote attack vector, public exploit, and high severity makes the risk significant for deployments that allow remote management of the device.

Generated by OpenCVE AI on August 14, 2026 at 09:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware release from TOTOLINK that addresses the setMacFilterRules buffer overflow.
  • If an immediate firmware upgrade is not possible, restrict or block external access to /cgi-bin/cstecgi.cgi and disable the firewall.so functionality until the patch is applied.
  • Configure the device to allow remote management only from trusted IP addresses and enforce strong authentication to reduce the likelihood of an attacker reaching the vulnerable endpoint.

Generated by OpenCVE AI on August 14, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a800r
Vendors & Products Totolink a800r

Fri, 14 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Title TOTOLINK A800R firewall.so cstecgi.cgi setMacFilterRules stack-based overflow
First Time appeared Totolink
Totolink a800r Firmware
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:o:totolink:a800r_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a800r Firmware
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A800r A800r Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-14T08:00:11.323Z

Reserved: 2026-08-14T00:55:43.526Z

Link: CVE-2026-19813

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T08:17:38.427

Modified: 2026-08-14T08:17:38.427

Link: CVE-2026-19813

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T10:00:03Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow