CVE-2025-28019: Buffer Overflow
Published Apr 23, 2025
·Updated
TOTOLINK A800R V4.1.2cu.5137B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi component
Affected Software
3 affected components
TOTOLINK A800R
All of the following
TOTOLINK A800r Firmware=4.1.2cu.5137_b20200730
TOTOLINK A800R
Event History
Apr 23, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-28019?
CVE-2025-28019 is considered a critical vulnerability due to its buffer overflow nature that could lead to remote code execution.
2
How do I fix CVE-2025-28019?
To fix CVE-2025-28019, update the firmware of TOTOLINK A800R to the latest version provided by the vendor.
3
What component is affected by CVE-2025-28019?
The downloadFile.cgi component is the specific area affected by CVE-2025-28019.
4
Can CVE-2025-28019 be exploited remotely?
Yes, CVE-2025-28019 can be exploited remotely, allowing attackers to execute arbitrary code on the affected device.
5
Which devices are vulnerable to CVE-2025-28019?
The TOTOLINK A800R router with firmware version V4.1.2cu.5137_B20200730 is vulnerable to CVE-2025-28019.