Cyber & AI intelligence
Wasteland.
Briefs indexed2326
Issues25
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-82539 2026-08-30

CVE-2026-82539: Memory Corruption in TOTOLINK A720R MAC Filtering

"A publicly disclosed memory corruption flaw in the TOTOLINK A720R router's MAC filtering handler carries a CVSS 3.1 score of 9.1 (Critical) and can be triggered remotely."

A publicly disclosed memory corruption flaw in the TOTOLINK A720R router's MAC filtering handler carries a CVSS 3.1 score of 9.1 (Critical) and can be triggered remotely.

What Is It

CVE-2026-82539 is a memory corruption vulnerability (CWE-119, improper restriction of operations within the bounds of a memory buffer) in the setMacFilterRules function of cstecgi.cgi, part of the MAC Filtering component in TOTOLINK A720R firmware. Manipulating the desc argument leads to memory corruption. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

The record was published 2026-08-30 by VulDB ([email protected]) and is currently in "Received" status at NVD.

Why It Matters

The CVSS 3.1 base score is 9.1 (Critical), vector AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, network attack vector, low attack complexity, no user interaction, and a changed scope with high confidentiality, integrity, and availability impact. All scoring in the record originates from VulDB as the assigning CNA, not from TOTOLINK: VulDB additionally rates the issue 8.5 (High) under CVSS 4.0 with an exploit maturity of Proof-of-Concept, and assigns a CVSS 2.0 score of 8.3.

The mitigating factor is privileges: both the 3.1 and 4.0 vectors require high privileges (PR:H), and CVSS 2.0 lists multiple authentication instances. Exploitation is not anonymous, but a public proof-of-concept exists and the scope change means impact extends beyond the vulnerable component.

There is no CISA KEV entry for this CVE. Active exploitation is not confirmed by KEV, and no KEV-mandated remediation deadline or required action applies.

What's Vulnerable

Patch Status

No patch, fixed version, or vendor advisory is listed in the supplied NVD record. The only vendor reference provided is the TOTOLINK homepage. No remediation guidance or required action is specified in the source data.

Sources