TOTOLINK CP450 cstecgi.cgi Buffer Overflow

Release Date: 3rd September 2026

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations, Internet Service Providers, and System/Network administrators that deploy the TOTOLINK CP450 outdoor wireless access point/CPE, including any operator using it to deliver wireless broadband links. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-85031 is a critical buffer overflow vulnerability in the TOTOLINK CP450, a 5GHz outdoor wireless access point/client (CPE) device by TOTOLINK, a global consumer and small-ISP networking hardware vendor, marketed for long-range point-to-point and point-to-multipoint wireless links of the kind used by wireless internet service providers (WISPs) and rural broadband operators. The flaw lies in the device’s web-management interface, in an unspecified function of /cgi-bin/cstecgi.cgi, where manipulation of the "topicurl" argument triggers a buffer overflow.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-85031
  2. https://www.totolink.net/product/CP450