← Terug naar overzicht

A vulnerability identified as CVE-2026-82539 affects TOTOLINK A720R firmware version 4.1.5cu.630_B20250509. The flaw resides in the setMacFilterRules function within the cstecgi.cgi file, specifically in the MAC Filtering component. Manipulation of the 'desc' argument can trigger memory corruption, potentially allowing an attacker to execute arbitrary code or crash the device. The attack vector is remote, requiring no physical access to the target device. A public exploit has already been disclosed and is available for use, increasing the risk of active exploitation. TOTOLINK routers are commonly deployed in home and small business environments, widening the potential attack surface. The vulnerability poses a significant risk to network infrastructure security.

Affected products

  • TOTOLINK A720R 4.1.5cu.630_B20250509

Related CVE's

  • CVE-2026-82539

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities