CVE-2026-6157
HIGHTotolink A800R app.so setAppEasyWizardConfig buffer overflow
Title source: cnaDescription
A vulnerability was detected in Totolink A800R 4.1.2cu.5137_B20200730. This impacts the function setAppEasyWizardConfig in the library /lib/cste_modules/app.so. The manipulation of the argument apcliSsid results in buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.
Scores
CVSS v3
8.8
EPSS
0.0009
EPSS Percentile
24.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-119
CWE-120
Status
published
Products (1)
Totolink/A800R
4.1.2cu.5137_B20200730
Published
Apr 13, 2026
Tracked Since
Apr 13, 2026