Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-85031: TOTOLINK CP450 router allows remote takeover
CVE-2026-85031 · published today
Summary
The CP450 router’s web interface contains a flaw that can be triggered by sending a specially crafted request. An attacker could use this to run code on the device from anywhere on the internet. Update the router firmware or disable the vulnerable web feature until a fix is applied.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| totolink | cp450 | 4.1.0 |
Original advisory text
TOTOLINK CP450 cstecgi.cgi buffer overflow
A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote exploitation of the attack is possible.
References
- https://vuldb.com/vuln/398296 vdb-entry technical-description
- https://vuldb.com/vuln/398296/cti signature permissions-required
- https://vuldb.com/cve/CVE-2026-85031 third-party-advisory
- https://vuldb.com/submit/853096 third-party-advisory
- https://www.totolink.net/ product
Severity
9.9
Critical
CVSS 3.1: 9.9 (MITRE)
Type
CWE-120Classic Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen3 Sep 2026
Monitor software like this
Free during beta