CVE-2025-28025: Buffer Overflow
TOTOLINK A830R V4.1.2cu.5182B20201102, A950RG V4.1.2cu.5161B20200903, A3000RU V5.9c.5185B20201128, and A3100R V4.1.2cu.5247B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi through the v14 parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-28025?
CVE-2025-28025 has been classified with a high severity level due to its potential to allow remote code execution through buffer overflow.
How do I fix CVE-2025-28025?
To fix CVE-2025-28025, update your TOTOLINK A830R, A950RG, A3000RU, or A3100R firmware to the latest version provided by the vendor.
What products are affected by CVE-2025-28025?
The affected products include TOTOLINK A830R, A950RG, A3000RU, and A3100R routers.
What is the exploit of CVE-2025-28025?
CVE-2025-28025 allows attackers to exploit the vulnerability in downloadFile.cgi via the v14 parameter to cause a buffer overflow.
Is there a known workaround for CVE-2025-28025?
Currently, the recommended action is to apply the firmware update as there are no effective workarounds to mitigate CVE-2025-28025.