Sceawere

Vulnerability Detail

CVE-2026-85031UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TOTOLINK CP450 Buffer Overflow

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.9
Creation Date
4h ago
Vendor
TOTOLINK
Product
CP450
Attack Type
Buffer Overflow
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote exploitation of the attack is possible.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.9",
  "pubDate": "2026-09-03T13:06:19.767Z",
  "pubdate": "2026-09-03T13:06:19.767Z",
  "executiveSummary": "A critical memory corruption vulnerability exists in the TOTOLINK CP450, specifically within the /cgi-bin/cstecgi.cgi component. The vulnerability is identified as a buffer overflow triggered by improper handling of the 'topicurl' argument. This flaw allows a remote, unauthenticated attacker to manipulate input parameters to overwrite memory, potentially leading to arbitrary code execution or a denial-of-service state. The exposure of this CGI interface to the network facilitates remote exploitation without requiring prior authentication. Given the nature of buffer overflows in embedded web interfaces, successful exploitation may grant an attacker full control over the underlying operating system, resulting in complete device compromise, persistent access, or disruption of network services. Users are urged to restrict access to the web management interface and monitor for suspicious traffic targeting this specific endpoint.",
  "technicalDetails": "The vulnerability resides within the binary logic of the /cgi-bin/cstecgi.cgi executable on TOTOLINK CP450 firmware version 4.1.0. The vulnerability is classified as a stack-based buffer overflow caused by a failure to perform adequate bounds checking on the 'topicurl' parameter supplied during an HTTP request. When the cstecgi.cgi handler processes the request, it copies the user-supplied data from the 'topicurl' argument into a fixed-size stack buffer without verifying the length of the input. An attacker can craft a malicious HTTP request containing an oversized 'topicurl' payload that exceeds the destination buffer capacity. By carefully crafting this payload, the attacker can overwrite adjacent memory segments, including the saved return address on the stack. Upon completion of the function call, the processor restores the instruction pointer from the corrupted stack, redirecting the execution flow to an address controlled by the attacker. This mechanism enables the execution of shellcode injected as part of the payload or the deployment of return-oriented programming (ROP) chains to bypass non-executable stack protections. The attack flow involves a remote actor sending a specifically crafted HTTP GET or POST request directly to the vulnerable CGI interface. Since the /cgi-bin/cstecgi.cgi script is accessible to remote network participants, no authentication is required to reach the vulnerable code path. The exploitation of this flaw occurs during the routine parsing of CGI arguments, meaning the system is vulnerable as soon as the web service process handles the malicious input. The post-exploitation impact is severe, as the application typically runs with elevated privileges. Successful arbitrary code execution would allow an attacker to gain a root shell, install persistent backdoors, intercept network traffic, or pivot into the internal network segment connected to the CP450 device."
}
CVE-2026-85031: TOTOLINK CP450 Buffer Overflow (CRITICAL Severity, CVSS: 9.9) - Sceawere