criticalZero-Day

TOTOLINK A720R MAC Filtering Memory Corruption (cstecgi.cgi)

First seen Aug 31, 2026 · Updated Aug 31, 2026 · CVSS 9.1

iotroutermemory-corruptionremote-code-executionpublicly-disclosedtotolink

A critical remotely exploitable memory corruption vulnerability exists in TOTOLINK A720R routers running firmware 4.1.5cu.630_B20250509, affecting the setMacFilterRules function within cstecgi.cgi. The flaw is triggered via manipulation of the 'desc' argument in MAC filtering rules and has been publicly disclosed with exploit details available, increasing the likelihood of active exploitation.

Technical Analysis

The vulnerability resides in the setMacFilterRules function of cstecgi.cgi, part of the MAC Filtering component in TOTOLINK A720R firmware version 4.1.5cu.630_B20250509. Improper bounds checking or input sanitization on the 'desc' parameter allows an attacker to trigger memory corruption, potentially leading to remote code execution or denial of service on the device. The attack can be launched remotely without authentication details specified, and a CVSS score of 9.1 reflects high impact with low complexity of exploitation. Because a public exploit exists, threat actors and botnet operators (e.g., Mirai-style IoT malware) are likely to weaponize this quickly for mass scanning and compromise. Organizations deploying AI agents or edge inference workloads on or behind TOTOLINK-based network infrastructure could face compromised routers used as pivot points for credential theft, traffic interception, or man-in-the-middle attacks against agent API calls and RAG data flows, indirectly exposing API keys and agent-to-cloud communications.

Affected Systems

TOTOLINK A720R router, firmware version 4.1.5cu.630_B20250509, specifically the cstecgi.cgi component handling MAC Filtering (setMacFilterRules function)

Indicators of Compromise

  • N/A - No specific hashes, IPs, or domains provided in source data; monitor for anomalous requests to cstecgi.cgi with crafted 'desc' parameters in MAC filter rule submissions

Remediation Steps

  1. 1

    Apply Firmware Update

    Check TOTOLINK's official support channels for a patched firmware release addressing this vulnerability and apply it immediately once available.

  2. 2

    Restrict Remote Management Access

    Disable remote/WAN-facing administration interfaces on the router and restrict access to the management UI to trusted internal networks only.

  3. 3

    Network Segmentation

    Isolate IoT and networking devices like TOTOLINK routers from critical infrastructure, servers, and endpoints running AI agent or business-critical workloads.

  4. 4

    Monitor for Exploitation Attempts

    Deploy IDS/IPS signatures for known exploit patterns targeting cstecgi.cgi and setMacFilterRules, and monitor logs for unusual MAC filter rule modifications.

  5. 5

    Replace End-of-Life Hardware

    If no patch is issued, consider replacing affected TOTOLINK devices with actively supported networking hardware.

CVE / Advisory IDs

CVE-2026-82539

Industries Most Exposed

consumer electronicstelecommunicationssmall business networkingcritical infrastructure (SOHO/edge networks)technology

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.