CVE-2025-28018: Buffer Overflow
Published Apr 23, 2025
·Updated
TOTOLINK A800R V4.1.2cu.5137B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v14 parameter.
Affected Software
3 affected components
TOTOLINK A800R
All of the following
TOTOLINK A800r Firmware=4.1.2cu.5137_b20200730
TOTOLINK A800R
Event History
Apr 23, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-28018?
CVE-2025-28018 has a high severity rating due to the potential for remote code execution through buffer overflow.
2
How do I fix CVE-2025-28018?
To fix CVE-2025-28018, update the TOTOLINK A800R firmware to the latest version that addresses the vulnerability.
3
What is the exploit scenario for CVE-2025-28018?
The exploit scenario for CVE-2025-28018 involves an attacker sending a crafted request to the vulnerable downloadFile.cgi component.
4
Which devices are affected by CVE-2025-28018?
CVE-2025-28018 affects the TOTOLINK A800R with the firmware version V4.1.2cu.5137_B20200730.
5
Is CVE-2025-28018 a remote vulnerability?
Yes, CVE-2025-28018 is a remote vulnerability that can be exploited over the network without physical access to the device.