A remotely exploitable buffer overflow in the /cgi-bin/cstecgi.cgi endpoint of TOTOLINK CP450 firmware 4.1.0 can be triggered by manipulating the topicurl argument, with a CVSS 3.1 base score of 9.9 (CRITICAL).
What Is It
VulDB reported a vulnerability in TOTOLINK CP450 version 4.1.0 affecting an unknown function within the file /cgi-bin/cstecgi.cgi. Manipulation of the topicurl argument results in a buffer overflow, and remote exploitation is possible. The issue is classified under CWE-119 (improper restriction of operations within the bounds of a memory buffer) and CWE-120 (classic buffer overflow).
The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network-reachable, low attack complexity, no user interaction, but requiring low-level privileges. The changed scope combined with high confidentiality, integrity, and availability impact drives the 9.9 rating. A CVSS 4.0 secondary score of 8.6 (HIGH) is also assigned.
Why It Matters
cstecgi.cgi is the CGI handler that services the router's web management interface, so the vulnerable code path sits directly behind network-facing administration. The published CVSS 4.0 metrics indicate high impact to both the vulnerable system and subsequent systems, meaning a successful overflow is not contained to the affected component.
CISA's SSVC assessment for this CVE records exploitation as none and automatable as no, while rating technical impact as total. Exploitation status of "none" means there is no public proof-of-concept code and no observed in-the-wild activity for this CVE in the supplied data. Consistent with that, there is no CISA Known Exploited Vulnerabilities entry for CVE-2026-85031. The severity here is driven by the impact of the flaw itself and by the exposure of the web management interface, not by any current exploitation activity.
What's Vulnerable
- Vendor: TOTOLINK
- Product: CP450
- Affected version: 4.1.0 (firmware)
- CPE:
cpe:2.3:o:totolink:cp450_firmware:*:*:*:*:*:*:*:* - Vulnerable component: unknown function in
/cgi-bin/cstecgi.cgi, reached via thetopicurlargument
No other versions or products are listed in the source record.
Patch Status
The supplied NVD record contains no patch, fix version, or vendor advisory. Its status is Received as of 3 September 2026, and no CISA KEV required action or remediation due date applies since the CVE is not present in KEV. Operators should treat the affected firmware as unpatched and restrict access to the device's web management interface pending vendor guidance.
Sources
- NVD, CVE-2026-85031: https://nvd.nist.gov/vuln/detail/CVE-2026-85031
- VulDB, CVE-2026-85031: https://vuldb.com/cve/CVE-2026-85031
- VulDB, Vulnerability 398296: https://vuldb.com/vuln/398296
- VulDB, CTI details: https://vuldb.com/vuln/398296/cti
- VulDB, Submission 853096: https://vuldb.com/submit/853096
- TOTOLINK: https://www.totolink.net/