Description
A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-08-30
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A flaw in the setMacFilterRules function of the cstecgi.cgi file on TOTOLINK A720R routers permits an attacker to manipulate the desc argument, resulting in a buffer overflow that can corrupt memory. The data corruption may allow execution of arbitrary code or similar impact on the router’s integrity, confidentiality and availability. The vulnerability is classified as a memory corruption weakness identified by CWE-119.

Affected Systems

The affected product is the TOTOLINK A720R router running firmware version 4.1.5cu.630_B20250509. No other versions are listed as affected, but the vulnerability applies to all routers running this firmware revision.

Risk and Exploitability

The CVSS score of 9.4 indicates critical severity. The EPSS score is not available, so the exact likelihood of exploitation is unknown, but the vulnerability has been publicly disclosed and can be exploited remotely. It is not currently listed in the CISA KEV catalog. The attack vector is remote, relying on sending crafted requests to the router’s web interface to trigger the overflow.

Generated by OpenCVE AI on August 30, 2026 at 11:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router to the latest firmware revision that includes the fix for the MAC filtering function.
  • If an upgrade is not immediately possible, disable the MAC filtering feature or block access to cstecgi.cgi via the router’s firewall or access control settings to prevent the exploitation vector.
  • If the router must remain online, configure firewall rules to block traffic to the router’s management interface from untrusted networks or isolate the router in a separate network segment to reduce exposure.

Generated by OpenCVE AI on August 30, 2026 at 11:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 30 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a720r
Vendors & Products Totolink a720r

Sun, 30 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Title TOTOLINK A720R MAC Filtering cstecgi.cgi setMacFilterRules memory corruption
First Time appeared Totolink
Totolink a720r Firmware
Weaknesses CWE-119
CPEs cpe:2.3:o:totolink:a720r_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a720r Firmware
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Totolink A720r A720r Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-01T18:11:17.396Z

Reserved: 2026-08-29T17:39:50.384Z

Link: CVE-2026-82539

cve-icon Vulnrichment

Updated: 2026-09-01T17:08:13.715Z

cve-icon NVD

Status : Deferred

Published: 2026-08-30T11:17:35.067

Modified: 2026-09-01T19:17:28.633

Link: CVE-2026-82539

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-30T12:00:10Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer