Sceawere

Vulnerability Detail

CVE-2026-82539UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TOTOLINK A720R Memory Corruption Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
2h ago
Vendor
TOTOLINK
Product
A720R
Attack Type
Memory Corruption
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-30T11:17:35.067Z",
  "pubdate": "2026-08-30T11:17:35.067Z",
  "executiveSummary": "This vulnerability concerns a critical memory corruption flaw within the MAC Filtering component of the TOTOLINK A720R router, specifically affecting firmware version 4.1.5cu.630_B20250509.\nThe vulnerability originates in the setMacFilterRules function located within the cstecgi.cgi binary. By injecting malicious input into the 'desc' argument, an attacker can trigger memory corruption, which may lead to arbitrary code execution, denial of service, or unauthorized control over the device.\nThis flaw is remotely exploitable, meaning an attacker does not require physical access to the hardware to initiate the attack. The presence of a publicly disclosed exploit significantly increases the risk profile, allowing potentially unsophisticated actors to compromise the device.\nSuccessful exploitation poses severe security risks, including the potential for full system compromise, permanent denial of service (bricking), and interception of network traffic passing through the affected router.",
  "technicalDetails": "The vulnerability resides within the cstecgi.cgi CGI handler, which is responsible for processing administrative web requests for the TOTOLINK A720R. Specifically, the function setMacFilterRules fails to adequately sanitize or perform bounds checking on the 'desc' (description) parameter during the processing of MAC filtering rules.\nWhen a user submits a request to update MAC filtering settings, the application passes the 'desc' argument to an internal buffer without proper length validation. If an attacker provides a crafted string exceeding the allocated buffer size, a stack-based or heap-based buffer overflow occurs. This memory corruption overwrites adjacent memory addresses, potentially including return addresses, function pointers, or critical configuration data.\nThe attack flow begins with the attacker crafting an HTTP request targeted at the web management interface. By manipulating the 'desc' field with a specifically engineered payload, the attacker triggers the overflow during the execution of setMacFilterRules. Depending on the architecture, the overflow may allow the attacker to redirect the instruction pointer (IP/PC) to arbitrary code included within the payload, such as a ROP chain or shellcode.\nBecause this component operates with elevated privileges, successful exploitation allows the attacker to execute commands with the same authority as the web server process, potentially gaining full control over the underlying operating system. The vulnerability is network-exposed, allowing for remote exploitation if the management interface is accessible via the WAN or LAN interfaces.\nSince the exploit has been publicly disclosed, the barrier to entry for exploitation is low. The impact is significant, as it permits remote code execution, which can be leveraged for persistence, network reconnaissance, or lateral movement within the local area network. Given the nature of router firmware, standard memory protections (like ASLR or DEP/NX) may be absent or easily bypassed, facilitating reliable exploitation of the memory corruption condition."
}
CVE-2026-82539: TOTOLINK A720R Memory Corruption Vulnerability (CRITICAL Severity, CVSS: 9.1) - Sceawere