PT-2025-16340 · Totolink · Totolink A810R

CVE-2025-28137

·

Published

2025-04-15

·

Updated

2026-07-29

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK A810R version 4.1.2cu.5182 B20201026
Description The issue concerns a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter. This allows for unauthorized execution of commands.
Recommendations For version 4.1.2cu.5182 B20201026, consider disabling the setNoticeCfg function until a patch is available. Restrict access to the NoticeUrl parameter to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-05804
CVE-2025-28137

Affected Products

Totolink A810R