A vulnerability described as critical has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation of the argument pin results in stack-based buffer overflow.

This vulnerability is reported as CVE-2026-19847. The attack can be launched remotely. Moreover, an exploit is present.