First published: Wed Apr 23 2025(Updated: )
TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the downloadFile.cgi through the v14 and v3 parameters
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TOTOLINK A810R | ||
All of | ||
Totolink A3600r Firmware | =4.1.2cu.5182_b20201026 | |
TOTOLINK A810R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-28021 is categorized as a high severity vulnerability due to its potential to allow remote code execution on affected devices.
To fix CVE-2025-28021, users should update their TOTOLINK A810R firmware to the latest patched version released by the manufacturer.
CVE-2025-28021 is caused by a buffer overflow vulnerability in the downloadFile.cgi script when processing the v14 and v3 parameters.
CVE-2025-28021 affects devices running TOTOLINK A810R firmware version V4.1.2cu.5182_B20201026 and possibly earlier versions.
The potential impact of CVE-2025-28021 includes unauthorized remote access and execution of arbitrary code on vulnerable devices.