cbcvebase.

Totolink A800R vulnerabilities

11 known vulnerabilities affecting totolink/a800r.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10

Vulnerabilities

Page 1 of 1
CVE-2026-19813P2HIGHCVSS 8.8v4.1.2cu.5137_B202007302026-08-14
CVE-2026-19813 [HIGH] CWE-119 CVE-2026-19813: A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts th A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly
nvd
CVE-2026-19812P2HIGHCVSS 8.8v4.1.2cu.5137_B202007302026-08-14
CVE-2026-19812 [HIGH] CWE-119 CVE-2026-19812: A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function U A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation of the argument File causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the publ
nvd
CVE-2026-19846P2HIGHCVSS 8.8v4.1.2cu.5137_B202007302026-08-14
CVE-2026-19846 [HIGH] CWE-119 CVE-2026-19846: A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function s A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used.
nvd
CVE-2026-19847P2HIGHCVSS 8.8v4.1.2cu.5137_B202007302026-08-14
CVE-2026-19847 [HIGH] CWE-119 CVE-2026-19847: A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the functi A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation of the argument pin results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used f
nvd
CVE-2026-19814P2HIGHCVSS 8.8v4.1.2cu.5137_B202007302026-08-14
CVE-2026-19814 [HIGH] CWE-119 CVE-2026-19814: A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setM A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Performing a manipulation of the argument macAddress results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is now public and may be used.
nvd
CVE-2026-19811P2HIGHCVSS 8.8v4.1.2cu.5137_B202007302026-08-14
CVE-2026-19811 [HIGH] CWE-119 CVE-2026-19811: A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element i A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public
nvd
CVE-2026-19844P2HIGHCVSS 8.8v4.1.2cu.5137_B202007302026-08-14
CVE-2026-19844 [HIGH] CWE-119 CVE-2026-19844: A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the func A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component ipv6.so. Performing a manipulation of the argument radvdinterfacename results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made pu
nvd
CVE-2026-19815P2HIGHCVSS 8.8v4.1.2cu.5137_B202007302026-08-14
CVE-2026-19815 [HIGH] CWE-119 CVE-2026-19815: A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is th A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Executing a manipulation of the argument urlKeyword can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been pu
nvd
CVE-2025-4496P2CRITICALCVSS 9.8v4.1.8cu.5241_B202109272025-05-10
CVE-2025-4496 [CRITICAL] CWE-119 CVE-2025-4496: A vulnerability was found in TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU and A810R 4.1.8cu.5 A vulnerability was found in TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU and A810R 4.1.8cu.5241_B20210927. It has been declared as critical. This vulnerability affects the function CloudACMunualUpdate of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to buffer overflow. The attack can be initiated remotely. Th
nvd
CVE-2026-19845P2HIGHCVSS 8.8v4.1.2cu.5137_B202007302026-08-14
CVE-2026-19845 [HIGH] CWE-119 CVE-2026-19845: A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function s A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed
nvd
CVE-2026-6157P2HIGHCVSS 8.8v4.1.2cu.5137_B202007302026-04-13
CVE-2026-6157 [HIGH] CWE-119 CVE-2026-6157: A vulnerability was detected in Totolink A800R 4.1.2cu.5137_B20200730. This impacts the function set A vulnerability was detected in Totolink A800R 4.1.2cu.5137_B20200730. This impacts the function setAppEasyWizardConfig in the library /lib/cste_modules/app.so. The manipulation of the argument apcliSsid results in buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.
nvd
Totolink A800R vulnerabilities | cvebase