A800r Firmware Totolink A800r Firmware

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Totolink A800r Firmware.

By the Year

In 2026 there have been 10 vulnerabilities in Totolink A800r Firmware with an average score of 8.7 out of ten. Last year, in 2025 A800r Firmware had 6 security vulnerabilities published. That is, 4 more vulnerabilities have already been reported in 2026 as compared to last year.

Year Vulnerabilities Average Score
2026 10 8.71
2025 6 0.00

It may take a day or so for new A800r Firmware vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Totolink A800r Firmware Security Vulnerabilities

TOTOLINK A800R 4.1.2cu.5137_B20200730: wps.so BOP via setWiFiWpsConfig
CVE-2026-19847 8.7 - High - August 14, 2026

A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation of the argument pin results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

Stack Overflow

TOTOLINK A800R v4.1.2cu.5137 stackbased buffer overflow via URL filter
CVE-2026-19846 8.7 - High - August 14, 2026

A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used.

Stack Overflow

Buffer Overflow in lan.so of TOTOLINK A800R 4.1.2cu via setStaticDhcpConfig
CVE-2026-19845 8.7 - High - August 14, 2026

A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.

Stack Overflow

IPv6 Buffer Overflow in TOTOLINK A800R via setRadvdCfg (radvdiface) vuln 4.1.2
CVE-2026-19844 8.7 - High - August 14, 2026

A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component ipv6.so. Performing a manipulation of the argument radvdinterfacename results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

Stack Overflow

TOTOLINK A800R 4.1.2cu.5137 B20200730 Stack-Based BF in firewall.so
CVE-2026-19815 8.7 - High - August 14, 2026

A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Executing a manipulation of the argument urlKeyword can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.

Stack Overflow

Stack-based Buffer Overflow in firewall.so of TOTOLINK A800R 4.1.2cu.5137_B20200730
CVE-2026-19814 8.7 - High - August 14, 2026

A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Performing a manipulation of the argument macAddress results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is now public and may be used.

Stack Overflow

Stack Buffer Overflow in TOTOLINK A800R 4.1.2cu.5137_B20200730 firewall.so
CVE-2026-19813 8.7 - High - August 14, 2026

A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

Stack Overflow

TOTOLINK A800R 4.1.2 cu stack-buf overflow via UploadCustomModule
CVE-2026-19812 8.7 - High - August 14, 2026

A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation of the argument File causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

Stack Overflow

TOTOLINK A800R 4.1.2cu stack overflow in firewall.so
CVE-2026-19811 8.7 - High - August 14, 2026

A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

Stack Overflow

Totolink A800R 4.1.2cu Buffer Overflow via apcliSsid (setAppEasyWizardConfig)
CVE-2026-6157 8.8 - High - April 13, 2026

A vulnerability was detected in Totolink A800R 4.1.2cu.5137_B20200730. This impacts the function setAppEasyWizardConfig in the library /lib/cste_modules/app.so. The manipulation of the argument apcliSsid results in buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.

Classic Buffer Overflow

TOTOLINK A800R V4.1.2cu.5137_B20200730 Buffer Overflow in downloadFile.cgi v25
CVE-2025-28020 - April 23, 2025

TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.

TOTOLINK A800R V4.1.2cu.5137_B20200730 Buffer Overflow in downloadFile.cgi
CVE-2025-28019 - April 23, 2025

TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi component

TOTOLINK A800R V4.1.2cu.5137_B20200730 Buffer Overflow in downloadFile.cgi (v14)
CVE-2025-28018 - April 23, 2025

TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v14 parameter.

Cmd Injt in downloadFile.cgi on TOTOLINK A800R (v4.1.2cu.5032_B20200408)
CVE-2025-28017 - April 23, 2025

TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter.

TOTOLINK A800R V4.1.2cu Buffer Overflow in downloadFile.cgi
CVE-2025-28136 - April 15, 2025

TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi.

Pre-Auth RCE in TOTOLINK A800R V4.1.2cu.5137_B20200730 setNoticeCfg via NoticeUrl
CVE-2025-28138 - March 27, 2025

The TOTOLINK A800R V4.1.2cu.5137_B20200730 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Totolink A800r Firmware or by Totolink? Click the Watch button to subscribe.

Totolink
Vendor

subscribe