PT-2025-17650 · Totolink · Totolink A810R

CVE-2025-28022

·

Published

2025-04-23

·

Updated

2025-04-28

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TOTOLINK A810R version 4.1.2cu.5182 B20201026
Description A buffer overflow issue was discovered in the downloadFile.cgi endpoint through the v25 parameter.
Recommendations For TOTOLINK A810R version 4.1.2cu.5182 B20201026, avoid using the v25 parameter in the "downloadFile.cgi" endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the downloadFile.cgi endpoint to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-10010
CVE-2025-28022

Affected Products

Totolink A810R