Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-85031: TOTOLINK CP450 router allows remote takeover

CVE-2026-85031 · published today
Summary

The CP450 router’s web interface contains a flaw that can be triggered by sending a specially crafted request. An attacker could use this to run code on the device from anywhere on the internet. Update the router firmware or disable the vulnerable web feature until a fix is applied.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
totolink cp450 4.1.0
Original advisory text
TOTOLINK CP450 cstecgi.cgi buffer overflow
A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote exploitation of the attack is possible.
References
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
Type
CWE-120Classic Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen3 Sep 2026
Sources
CVE-2026-85031 · MITRE
Monitor software like this
Free during beta