Description
A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-08-14
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack-based buffer overflow was found in TOTOLINK A800R firmware version 4.1.2cu.5137_B20200730. The vulnerability is triggered by manipulating the Comment parameter in the cstecgi.cgi component, allowing an attacker to overflow the stack and potentially execute arbitrary code from a remote location.

Affected Systems

The affected product is the TOTOLINK A800R router running firmware 4.1.2cu.5137_B20200730. No other versions or products are currently listed as vulnerable.

Risk and Exploitability

The flaw carries a CVSS score of 8.7, indicating high severity. EPSS information is not available, and the vulnerability is not listed in CISA's KEV catalog, but the exploit has been publicly disclosed and can be launched remotely, making it likely that attackers could target vulnerable devices if they are reachable from the internet.

Generated by OpenCVE AI on August 14, 2026 at 18:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from TOTOLINK that resolves the setStaticDhcpConfig overflow.
  • If an update is not possible, block external access to the cstecgi.cgi endpoint using firewall rules or router access control lists to mitigate the remote exploitation risk.
  • Continuously monitor router logs for suspicious requests to cstecgi.cgi and investigate any indications of attempted exploitation.

Generated by OpenCVE AI on August 14, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a800r
Vendors & Products Totolink a800r

Fri, 14 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Title TOTOLINK A800R lan.so cstecgi.cgi setStaticDhcpConfig stack-based overflow
First Time appeared Totolink
Totolink a800r Firmware
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:o:totolink:a800r_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a800r Firmware
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A800r A800r Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-14T17:37:51.259Z

Reserved: 2026-08-14T08:04:34.036Z

Link: CVE-2026-19845

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T17:17:35.753

Modified: 2026-08-14T18:17:23.747

Link: CVE-2026-19845

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T18:30:07Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow