CVE-2025-28017: Command Injection
Published Apr 23, 2025
·Updated
TOTOLINK A800R V4.1.2cu.5032B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERYSTRING parameter.
Affected Software
3 affected components
TOTOLINK A800R
All of the following
TOTOLINK A800r Firmware=4.1.2cu.5032_b20200408
TOTOLINK A800R
Event History
Apr 23, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-28017?
CVE-2025-28017 has been rated as a high severity vulnerability due to the potential for remote command execution.
2
How do I fix CVE-2025-28017?
To fix CVE-2025-28017, you should update the TOTOLINK A800R firmware to a patched version as recommended by the vendor.
3
What type of vulnerability is CVE-2025-28017?
CVE-2025-28017 is classified as a command injection vulnerability affecting the downloadFile.cgi script.
4
Which devices are affected by CVE-2025-28017?
CVE-2025-28017 specifically affects the TOTOLINK A800R with firmware version V4.1.2cu.5032_B20200408.
5
What is the potential impact of exploiting CVE-2025-28017?
Exploiting CVE-2025-28017 could allow an attacker to execute arbitrary commands on the affected device.