{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3htotolinka720r4.1.5cu.630_b20250509/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:h:totolink:a720r:4.1.5cu.630_b20250509:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-82539"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["A720R (4.1.5cu.630_B20250509)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["TOTOLINK"],"content_html":"\u003cp\u003eTOTOLINK A720R firmware version 4.1.5cu.630_B20250509 contains a critical memory corruption vulnerability identified as CVE-2026-82539. The flaw resides within the setMacFilterRules function of the cstecgi.cgi component, which handles MAC filtering configurations. An unauthenticated remote attacker can exploit this vulnerability by sending a maliciously crafted HTTP request containing an oversized or malformed 'desc' argument to the affected interface. This manipulation triggers a memory corruption condition, which may result in a device crash (Denial of Service) or potential arbitrary code execution. Given the public disclosure of exploit details, organizations utilizing these devices in internet-facing configurations are at significant risk of remote compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows remote attackers to compromise the availability and integrity of TOTOLINK A720R network devices. Successful exploitation can lead to a complete denial of service for the network segment managed by the router or provide a foothold for further unauthorized access into the internal network environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eRestrict administrative access to the router's web interface to trusted management subnets only.\u003c/li\u003e\n\u003cli\u003eMonitor incoming HTTP traffic directed at the cstecgi.cgi endpoint for anomalous request patterns or excessively long arguments in the 'desc' parameter.\u003c/li\u003e\n\u003cli\u003eConsult the vendor for firmware update availability and apply patches immediately once released.\u003c/li\u003e\n\u003cli\u003eImplement network-level egress filtering to prevent exploited devices from reaching external command and control infrastructure.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-30T13:10:23Z","date_published":"2026-08-30T13:10:23Z","id":"https://feed.craftedsignal.io/briefs/2026-08-30-totolink-memory-corruption/","summary":"A remote memory corruption vulnerability in the TOTOLINK A720R router allows unauthenticated attackers to trigger a crash or potentially achieve code execution via the cstecgi.cgi script.","title":"Remote Memory Corruption in TOTOLINK A720R MAC Filtering","url":"https://feed.craftedsignal.io/briefs/2026-08-30-totolink-memory-corruption/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:h:totolink:a720r:4.1.5cu.630_b20250509:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}