CVE-2025-28026: Buffer Overflow
Published Apr 22, 2025
·Updated
TOTOLINK A830R V4.1.2cu.5182B20201102, A950RG V4.1.2cu.5161B20200903, A3000RU V5.9c.5185B20201128, and A3100R V4.1.2cu.5247B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi.
Affected Software
12 affected components
TOTOLINK A830R
TOTOLINK A950RG
TOTOLINK A3000RU
TOTOLINK A3100R
All of the following
TOTOLINK A830r Firmware=4.1.2cu.5182_b20201102
TOTOLINK A830R
All of the following
TOTOLINK A950rg Firmware=4.1.2cu.5161_b20200903
TOTOLINK A950RG
All of the following
TOTOLINK A3000ru Firmware=5.9c.5185_b20201128
TOTOLINK A3000RU
All of the following
TOTOLINK A3100r Firmware=4.1.2cu.5247_b20211129
TOTOLINK A3100R
Event History
Apr 22, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-28026?
CVE-2025-28026 has a high severity due to its buffer overflow characteristic that can lead to code execution.
2
How do I fix CVE-2025-28026?
To fix CVE-2025-28026, update the firmware of affected TOTOLINK devices to the latest version provided by the manufacturer.
3
Which devices are affected by CVE-2025-28026?
CVE-2025-28026 affects TOTOLINK devices including A830R, A950RG, A3000RU, and A3100R with specific firmware versions.
4
What type of vulnerability is CVE-2025-28026?
CVE-2025-28026 is a buffer overflow vulnerability found in the downloadFile.cgi component.
5
What could be the impact of exploiting CVE-2025-28026?
Exploiting CVE-2025-28026 could allow an attacker to execute arbitrary code on the affected devices.