PT-2025-17653 · Totolink · Totolink A810R

CVE-2025-28021

·

Published

2025-04-23

·

Updated

2025-04-28

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TOTOLINK A810R version 4.1.2cu.5182 B20201026
Description A buffer overflow issue was discovered in the downloadFile.cgi, specifically through the v14 and v3 parameters.
Recommendations For TOTOLINK A810R version 4.1.2cu.5182 B20201026, as a temporary workaround, consider restricting access to the downloadFile.cgi endpoint until a patch is available. Avoid using the v14 and v3 parameters in the affected endpoint until the issue is resolved.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-10009
CVE-2025-28021

Affected Products

Totolink A810R