CVE-2025-28020: Buffer Overflow
Published Apr 23, 2025
·Updated
TOTOLINK A800R V4.1.2cu.5137B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.
Affected Software
3 affected components
TOTOLINK A800R
All of the following
TOTOLINK A800r Firmware=4.1.2cu.5137_b20200730
TOTOLINK A800R
Event History
Apr 23, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-28020?
CVE-2025-28020 has been classified with a high severity due to its buffer overflow vulnerability.
2
How do I fix CVE-2025-28020?
To fix CVE-2025-28020, update the TOTOLINK A800R firmware to the latest version that addresses this vulnerability.
3
What is the potential impact of CVE-2025-28020?
The potential impact of CVE-2025-28020 includes remote code execution and denial of service on the affected device.
4
What devices are affected by CVE-2025-28020?
CVE-2025-28020 affects the TOTOLINK A800R devices running firmware version V4.1.2cu.5137_B20200730.
5
Is CVE-2025-28020 exploitable by remote attackers?
Yes, CVE-2025-28020 is exploitable by remote attackers without authentication, making it particularly dangerous.