← Terug naar overzicht

A buffer overflow vulnerability has been identified in TOTOLINK CP450 version 4.1.0. The vulnerability resides in an unknown function within the /cgi-bin/cstecgi.cgi file. By manipulating the 'topicurl' argument, an attacker can trigger a buffer overflow condition. The vulnerability is remotely exploitable, making it accessible to attackers without physical access to the device. TOTOLINK CP450 is a network router/access point device, placing this vulnerability in the network infrastructure category. The flaw could potentially allow remote code execution or denial of service. No authentication requirements for exploitation are mentioned, which increases the severity. The vulnerability has been assigned CVE-2026-85031 and is tracked in the NVD and VulDB databases.

Affected products

  • TOTOLINK CP450 4.1.0

Related CVE's

  • CVE-2026-85031

Categories

  • Mobile & IoT
  • Network Infrastructure