CVE-2026-82539
PoC largeAuthenticated memory corruption in TOTOLINK A720R MAC filtering
CVE-2026-82539 is a memory-corruption flaw (CWE-119) in the setMacFilterRules function of the cstecgi.cgi CGI handler on TOTOLINK A720R routers, affecting the MAC Filtering component. An attacker sends a crafted "desc" argument in a MAC filtering rules request, and the mishandled input corrupts memory; the CVSS 4.0 vector (AV:N/PR:H/UI:N) indicates the attack is remote but requires high privileges, i.e., an authenticated administrator session on the router's web interface. Exploitation is scored 8.5 (High) with high impact to confidentiality, integrity, and availability, consistent with device compromise or denial of service, though the advisory does not confirm a specific outcome such as remote code execution. Only firmware 4.1.5cu.630_B20250509 is named as affected, so TOTOLINK A720R units running that build are in scope, and no fixed version is provided in the data. The advisory states the exploit has been publicly disclosed and may be utilized (CVSS 4.0 exploit maturity is marked proof-of-concept), but the flaw is not in CISA KEV and EPSS estimates only a 0.6% probability of exploitation within 30 days (47th percentile).
What to do: Check TOTOLINK's download center for an A720R firmware release newer than 4.1.5cu.630_B20250509 and upgrade, as no fixed version is identified in the available data. Until patched, do not expose the router's admin web UI (cstecgi.cgi) to the WAN, restrict management to trusted LAN clients, and use strong admin credentials, since exploitation requires authenticated administrator access. Monitor CISA KEV and this dashboard for changes in exploitation status given the disclosed PoC.
| TOTOLINK A720R router (cstecgi.cgi, MAC Filtering component) | firmware 4.1.5cu.630_B20250509 (only build named in the advisory; no fixed version specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
- Weakness
- CWE-119
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.