PT-2025-16340 · Totolink · Totolink A810R

CVE-2025-28137

·

Publicado

2025-04-15

·

Atualizado

2026-07-29

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK A810R version 4.1.2cu.5182 B20201026
Description The issue concerns a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter. This allows for unauthorized execution of commands.
Recommendations For version 4.1.2cu.5182 B20201026, consider disabling the setNoticeCfg function until a patch is available. Restrict access to the NoticeUrl parameter to minimize the risk of exploitation.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-05804
CVE-2025-28137

Produtos afetados

Totolink A810R