Skip to content
Threat Feed
critical advisory

Buffer Overflow in TOTOLINK CP450

A critical buffer overflow vulnerability (CVE-2026-85031) in the TOTOLINK CP450 web interface allows remote, unauthenticated attackers to execute arbitrary code via the 'topicurl' argument.

CVE search metadata

CVE search record: CVE-2026-85031. Severity: critical. CVSS: 9.9. KEV: no. Product: CP450 (4.1.0). Brief: Buffer Overflow in TOTOLINK CP450. Brief link: https://feed.craftedsignal.io/briefs/2026-09-totolink-cve/

TOTOLINK CP450 firmware version 4.1.0 contains a critical buffer overflow vulnerability identified as CVE-2026-85031. The vulnerability resides within the '/cgi-bin/cstecgi.cgi' script, which handles web-based administrative requests. An unauthenticated remote attacker can exploit this by sending a crafted HTTP request with an excessively long 'topicurl' parameter. This manipulation triggers a memory corruption event within the device process handling the CGI request. Given the 9.9 CVSS score, successful exploitation likely leads to remote code execution (RCE) with the privileges of the web service, typically resulting in full device compromise or permanent denial of service. Defenders should prioritize patching or restricting access to the management interface of affected devices, as these systems are often exposed to the internet.

Impact

The vulnerability poses a severe risk to organizations using the TOTOLINK CP450, as successful exploitation allows full control over the network device. This may lead to the exfiltration of network traffic, unauthorized internal network access, or the deployment of persistent botnet malware. Due to the nature of the device as a network-edge component, a compromised unit can serve as a pivot point for lateral movement into the protected internal environment.

Recommendation

  • Restrict access to the device management interface (/cgi-bin/cstecgi.cgi) to trusted management VLANs or internal IP ranges only.
  • Monitor web logs for anomalous HTTP POST/GET requests directed at /cgi-bin/cstecgi.cgi containing unusually large strings in the 'topicurl' parameter.
  • Check for vendor firmware updates and apply them immediately to all deployed TOTOLINK CP450 units.

Immediate actions

Restrict external network access to the CP450 web management interface.

Network Security 24h

Mitigations

Upgrade or replace affected CP450 devices if firmware updates are available.

immediate IT Operations

CVE-2026-85031