A vulnerability labeled as critical has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-based buffer overflow.

This vulnerability is registered as CVE-2026-19845. It is possible to launch the attack remotely. Furthermore, an exploit is available.