


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC…
Published:
30 August 2026 at 00:00:00
Alert date:
30 August 2026 at 14:00:32
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure, Zero-Day Vulnerabilities
A vulnerability identified as CVE-2026-82539 affects TOTOLINK A720R firmware version 4.1.5cu.630_B20250509. The flaw resides in the setMacFilterRules function within the cstecgi.cgi file, specifically in the MAC Filtering component. Manipulation of the 'desc' argument can trigger memory corruption, potentially allowing an attacker to execute arbitrary code or crash the device. The attack vector is remote, requiring no physical access to the target device. A public exploit has already been disclosed and is available for use, increasing the risk of active exploitation. TOTOLINK routers are commonly deployed in home and small business environments, widening the potential attack surface. The vulnerability poses a significant risk to network infrastructure security.
Technical details
Mitigation steps:
Affected products:
TOTOLINK A720R 4.1.5cu.630_B20250509
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82539
https://github.com/Xernary/CVE-2026-82539
https://vuldb.com/cve/CVE-2026-82539
https://vuldb.com/submit/888696
https://vuldb.com/vuln/397055
https://vuldb.com/vuln/397055/cti
https://www.totolink.net/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
