First published: Wed Apr 23 2025(Updated: )
TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A800R firmware | ||
All of | ||
TOTOLink A800R | =4.1.2cu.5032_b20200408 | |
Totolink A800R firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-28017 has been rated as a high severity vulnerability due to the potential for remote command execution.
To fix CVE-2025-28017, you should update the TOTOLINK A800R firmware to a patched version as recommended by the vendor.
CVE-2025-28017 is classified as a command injection vulnerability affecting the downloadFile.cgi script.
CVE-2025-28017 specifically affects the TOTOLINK A800R with firmware version V4.1.2cu.5032_B20200408.
Exploiting CVE-2025-28017 could allow an attacker to execute arbitrary commands on the affected device.