Impact
An overrun occurs when an attacker sends a crafted value to the topicurl argument of /cgi-bin/cstecgi.cgi, causing a buffer overflow that can be leveraged for arbitrary code execution on the router. The weakness is categorized as CWE‑119 and CWE‑120, reflecting improper bounds checking and unsafe memory handling. The vulnerability is openly reachable over the network, allowing an attacker to trigger the overflow without local access.
Affected Systems
Only the TOTOLINK CP450 router with firmware version 4.1.0 is documented as affected. No other vendor models or firmware releases are mentioned, so the risk is confined to that specific combination.
Risk and Exploitability
The issue carries a CVSS score of 9.4, indicating critical severity, and its EPSS score is currently unknown. It is not listed in CISA's KEV catalogue. Because the exploit is remote and requires only an HTTP request to the exposed CGI handler, the attack surface is high. An attacker would send a malicious request to /cgi-bin/cstecgi.cgi from an external network to trigger the overflow and potentially take control of the router.
OpenCVE Enrichment