<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:h:totolink:a720r:4.1.5cu.630_b20250509:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3htotolinka720r4.1.5cu.630_b20250509/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 30 Aug 2026 13:10:23 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3htotolinka720r4.1.5cu.630_b20250509/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Memory Corruption in TOTOLINK A720R MAC Filtering</title><link>https://feed.craftedsignal.io/briefs/2026-08-30-totolink-memory-corruption/</link><pubDate>Sun, 30 Aug 2026 13:10:23 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-30-totolink-memory-corruption/</guid><description>A remote memory corruption vulnerability in the TOTOLINK A720R router allows unauthenticated attackers to trigger a crash or potentially achieve code execution via the cstecgi.cgi script.</description><content:encoded><![CDATA[<p>TOTOLINK A720R firmware version 4.1.5cu.630_B20250509 contains a critical memory corruption vulnerability identified as CVE-2026-82539. The flaw resides within the setMacFilterRules function of the cstecgi.cgi component, which handles MAC filtering configurations. An unauthenticated remote attacker can exploit this vulnerability by sending a maliciously crafted HTTP request containing an oversized or malformed 'desc' argument to the affected interface. This manipulation triggers a memory corruption condition, which may result in a device crash (Denial of Service) or potential arbitrary code execution. Given the public disclosure of exploit details, organizations utilizing these devices in internet-facing configurations are at significant risk of remote compromise.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows remote attackers to compromise the availability and integrity of TOTOLINK A720R network devices. Successful exploitation can lead to a complete denial of service for the network segment managed by the router or provide a foothold for further unauthorized access into the internal network environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Restrict administrative access to the router's web interface to trusted management subnets only.</li>
<li>Monitor incoming HTTP traffic directed at the cstecgi.cgi endpoint for anomalous request patterns or excessively long arguments in the 'desc' parameter.</li>
<li>Consult the vendor for firmware update availability and apply patches immediately once released.</li>
<li>Implement network-level egress filtering to prevent exploited devices from reaching external command and control infrastructure.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>