Remote Memory Corruption in TOTOLINK A720R MAC Filtering
A remote memory corruption vulnerability in the TOTOLINK A720R router allows unauthenticated attackers to trigger a crash or potentially achieve code execution via the cstecgi.cgi script.
CVE search metadata
CVE search record: CVE-2026-82539. Severity: critical. CVSS: 9.1. KEV: no. Product: A720R (4.1.5cu.630_B20250509). Brief: Remote Memory Corruption in TOTOLINK A720R MAC Filtering. Brief link: https://feed.craftedsignal.io/briefs/2026-08-30-totolink-memory-corruption/
TOTOLINK A720R firmware version 4.1.5cu.630_B20250509 contains a critical memory corruption vulnerability identified as CVE-2026-82539. The flaw resides within the setMacFilterRules function of the cstecgi.cgi component, which handles MAC filtering configurations. An unauthenticated remote attacker can exploit this vulnerability by sending a maliciously crafted HTTP request containing an oversized or malformed 'desc' argument to the affected interface. This manipulation triggers a memory corruption condition, which may result in a device crash (Denial of Service) or potential arbitrary code execution. Given the public disclosure of exploit details, organizations utilizing these devices in internet-facing configurations are at significant risk of remote compromise.
Impact
The vulnerability allows remote attackers to compromise the availability and integrity of TOTOLINK A720R network devices. Successful exploitation can lead to a complete denial of service for the network segment managed by the router or provide a foothold for further unauthorized access into the internal network environment.
Recommendation
- Restrict administrative access to the router's web interface to trusted management subnets only.
- Monitor incoming HTTP traffic directed at the cstecgi.cgi endpoint for anomalous request patterns or excessively long arguments in the 'desc' parameter.
- Consult the vendor for firmware update availability and apply patches immediately once released.
- Implement network-level egress filtering to prevent exploited devices from reaching external command and control infrastructure.
Immediate actions
Restrict management interface access to internal subnets.
Mitigations
Apply manufacturer firmware patch when available.
CVE-2026-82539