Junglewise Threat Intelligence

CVE-2026-6157: Totolink A800R buffer overflow in setAppEasyWizardConfig

CVE-2026-6157 · Severity: high · CVSS 8.8 · Published 2026-04-13

Vendors: TOTOLINK.

Executive brief

A security vulnerability exists in the Totolink A800R wireless router, a device used to provide home and small office internet connectivity. An attacker can exploit this flaw to crash the router or potentially take full control of the device by sending a specially crafted web request. This could lead to a complete loss of internet service or unauthorized access to the network traffic passing through the router.

Technical details

A stack-based buffer overflow (CWE-121) exists in the 'setAppEasyWizardConfig' function within the '/lib/cste_modules/app.so' library of the Totolink A800R router. The vulnerability is caused by the unsafe use of 'strcpy' when processing the 'apcliSsid' parameter retrieved via 'websGetVar'. The function copies this user-supplied input into a fixed-size 32-byte stack buffer without performing bounds checking. A remote attacker with low privileges can exploit this by sending a crafted POST request to '/cgi-bin/cstecgi.cgi', leading to memory corruption, service crashes, or potential arbitrary code execution. A public proof-of-concept (PoC) is available.

Affected products

  • Totolink A800R 4.1.2cu.5137_B20200730

Timeline

  • 2026-04-13: disclosed: Vulnerability reported via VulDB and NVD

References