A publicly disclosed memory corruption flaw in the TOTOLINK A720R router's MAC filtering handler carries a CVSS 3.1 score of 9.1 (Critical) and can be triggered remotely.
What Is It
CVE-2026-82539 is a memory corruption vulnerability (CWE-119, improper restriction of operations within the bounds of a memory buffer) in the setMacFilterRules function of cstecgi.cgi, part of the MAC Filtering component in TOTOLINK A720R firmware. Manipulating the desc argument leads to memory corruption. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
The record was published 2026-08-30 by VulDB ([email protected]) and is currently in "Received" status at NVD.
Why It Matters
The CVSS 3.1 base score is 9.1 (Critical), vector AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, network attack vector, low attack complexity, no user interaction, and a changed scope with high confidentiality, integrity, and availability impact. All scoring in the record originates from VulDB as the assigning CNA, not from TOTOLINK: VulDB additionally rates the issue 8.5 (High) under CVSS 4.0 with an exploit maturity of Proof-of-Concept, and assigns a CVSS 2.0 score of 8.3.
The mitigating factor is privileges: both the 3.1 and 4.0 vectors require high privileges (PR:H), and CVSS 2.0 lists multiple authentication instances. Exploitation is not anonymous, but a public proof-of-concept exists and the scope change means impact extends beyond the vulnerable component.
There is no CISA KEV entry for this CVE. Active exploitation is not confirmed by KEV, and no KEV-mandated remediation deadline or required action applies.
What's Vulnerable
- Vendor: TOTOLINK
- Product: A720R
- Affected version: firmware 4.1.5cu.630_B20250509
- Component: MAC Filtering,
setMacFilterRulesincstecgi.cgi - CPE:
cpe:2.3:o:totolink:a720r_firmware:*:*:*:*:*:*:*:*
Patch Status
No patch, fixed version, or vendor advisory is listed in the supplied NVD record. The only vendor reference provided is the TOTOLINK homepage. No remediation guidance or required action is specified in the source data.
Sources
- NVD, CVE-2026-82539: https://nvd.nist.gov/vuln/detail/CVE-2026-82539
- VulDB, CVE-2026-82539: https://vuldb.com/cve/CVE-2026-82539
- VulDB, Vulnerability 397055: https://vuldb.com/vuln/397055
- VulDB, CTI details: https://vuldb.com/vuln/397055/cti
- VulDB, Submission 888696: https://vuldb.com/submit/888696
- Public PoC (Xernary): https://github.com/Xernary/CVE-2026-82539
- TOTOLINK: https://www.totolink.net/