ZeroHour

CVE-2026-85031

moderate

Remote buffer overflow in TOTOLINK CP450 4.1.0 web interface

CVSS 4.0
8.6 high
EPSS
<1%p46
Published
()
Modified
AI analysis

TOTOLINK CP450 routers running firmware 4.1.0 contain a buffer overflow (CWE-119/CWE-120) in an unspecified function of the web management endpoint /cgi-bin/cstecgi.cgi. An attacker triggers the flaw by manipulating the topicurl argument sent to this endpoint over the network, and the CVSS 4.0 vector (PR:L) indicates some level of privileged/authenticated access is likely required. Successful exploitation causes memory corruption with high impact on the router's confidentiality, integrity and availability, potentially enabling code execution or a crash of the device. Only TOTOLINK CP450 devices on version 4.1.0 are known to be affected. There is currently no public proof-of-concept, no reported in-the-wild exploitation, and the device is not in CISA KEV; EPSS estimates only a ~0.6% chance of exploitation within 30 days.

What to do: Inventory for TOTOLINK CP450 devices running firmware 4.1.0 and check TOTOLINK's official site for a patched firmware release; do not expose the router's web management interface (cstecgi.cgi) directly to the internet, and restrict it to trusted management networks until a fix is available. Continue monitoring TOTOLINK advisories, since no public PoC exists yet but flaws of this type in TOTOLINK web endpoints have historically been rapidly weaponized.

Affected
TOTOLINK CP4504.1.0
Estimated exposure
moderateroughly 1,000-10,000 deployed or internet-exposed CP450 units (estimate, not a measured count) — Public internet scans have shown tens of thousands of TOTOLINK routers exposing the cstecgi.cgi web interface, but the CP450 is one older model among many TOTOLINK devices, suggesting only a moderate share of that population is affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote exploitation of the attack is possible.

Weakness
CWE-119, CWE-120
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.