CVE-2026-85031
9.9TOTOLINK · CP450
A buffer overflow vulnerability in the TOTOLINK CP450 /cgi-bin/cstecgi.cgi file allows authenticated remote attackers to execute arbitrary code via the topicurl argument.
Executive summary
The TOTOLINK CP450 device is susceptible to a critical buffer overflow vulnerability that could allow an authenticated remote attacker to achieve full system compromise.
Vulnerability
This is a memory corruption flaw categorized as a buffer overflow (CWE-120) occurring within the cgi-bin/cstecgi.cgi script. An attacker with low-level access can trigger this vulnerability by manipulating the topicurl argument, leading to potential remote code execution.
Business impact
The criticality of this vulnerability is underscored by its CVSS score of 9.9, which indicates the potential for complete loss of confidentiality, integrity, and availability. Successful exploitation grants an attacker significant control over the network device, which could facilitate lateral movement within the environment, data exfiltration, or total service disruption.
Remediation
Immediate Action: Contact the vendor or monitor the official TOTOLINK support portal for a firmware update that addresses this buffer overflow. If no patch is currently available, restrict network access to the management interface to trusted administrative subnets only.
Proactive Monitoring: Review system logs for unusual activity or unexpected crashes associated with the cstecgi.cgi process. Monitor inbound traffic to the management interface for anomalous patterns in the topicurl parameter.
Compensating Controls: Deploy a Web Application Firewall (WAF) or an Intrusion Prevention System (IPS) with signatures designed to detect and block malformed HTTP requests containing excessively long payloads in the topicurl parameter.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the critical severity score and the potential for remote code execution, this vulnerability poses a severe risk to network infrastructure. Administrators should prioritize identifying vulnerable CP450 units and restrict their exposure to external networks until an official vendor patch is applied. Immediate isolation of these devices from untrusted network segments is strongly advised to mitigate the threat of unauthorized access.
More TOTOLINK CVEs
Sources
Originally found and disclosed by summadeus (VulDB User), with VulDB Vulnerability Moderation Team (coordinator), per the CVE Program record.
- VDB-398296 | TOTOLINK CP450 cstecgi.cgi buffer overflow Vulnerability database entry
- VDB-398296 | CTI Indicators (IOB, IOC, IOA)
- CVE-2026-85031 | CVE Analysis and Report Third-party advisory
- Submit #853096 | TOTOLINK CP450 V4.1.0 Buffer Overflow Third-party advisory
- totolink.net