← Back
Network Infrastructure
CVE-2026-19811 high CVSS 8.8

A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted...

Summary

A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted...

AI summary openai / gpt-4o

TOTOLINK A800Rのバージョン4.1.2cu.5137_B20200730において、ファイル/cgi-bin/cstecgi.cgiのファイアウォールコンポーネント(firewall.so)のsetIpQosRules関数が脆弱です。この欠陥により、スタックベースのバッファオーバーフロー攻撃が可能となり、リモートから悪用される恐れがあります。問題の説明では、攻撃が公に利用可能であることが示されています。
❓ What is the problem
TOTOLINK A800RにおけるsetIpQosRules関数のスタックベースのバッファオーバーフロー。
📍 Affected scope
TOTOLINK A800Rバージョン4.1.2cu.5137_B20200730の/cgi-bin/cstecgi.cgiのコンポーネントfirewall.so。
🔥 Severity
CVSSスコア8.8の高いリスクで、リモート攻撃が可能。
🔧 How to fix
最新のファームウェアにアップデートすること。
🛡️ Workaround
ファイアウォールの該当機能を無効化する。
🔍 Detection
既知の攻撃パターンと一致するアクセスログを監視する。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →