Executive brief
TOTOLINK CP450 is a networking device used in corporate and home office environments. A remote attacker can exploit a buffer overflow vulnerability in the web administration interface by sending a specially crafted request to the cstecgi.cgi component, potentially allowing unauthorized code execution or device compromise without authentication.
Technical details
The vulnerability is a stack-based buffer overflow in the /cgi-bin/cstecgi.cgi endpoint of TOTOLINK CP450 version 4.1.0. The flaw exists in an unknown function that processes the "topicurl" parameter without proper input validation or bounds checking. The vulnerability is remotely exploitable over the network without requiring prior authentication. A successful exploit allows an attacker to execute arbitrary code on the device with the privileges of the web service process, potentially gaining full device control.
Affected products
- TOTOLINK CP450 4.1.0
Timeline
- 2026-09-03: disclosed