PT-2025-17648 · Totolink · Totolink A800R

CVE-2025-28019

·

Published

2025-04-23

·

Updated

2025-05-06

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TOTOLINK A800R version 4.1.2cu.5137 B20200730
Description A buffer overflow vulnerability was found in the downloadFile.cgi component. This issue affects the TOTOLINK A800R router.
Recommendations For version 4.1.2cu.5137 B20200730, as a temporary workaround, consider disabling the downloadFile.cgi component until a patch is available. Restrict access to the downloadFile.cgi component to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-10007
CVE-2025-28019

Affected Products

Totolink A800R