CVE-2025-28028: Buffer Overflow
Published Apr 23, 2025
·Updated
TOTOLINK A830R V4.1.2cu.5182B20201102, A950RG V4.1.2cu.5161B20200903, A3000RU V5.9c.5185B20201128, and A3100R V4.1.2cu.5247B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi through the v5 parameter.
Affected Software
12 affected components
TOTOLINK A830R
TOTOLINK A950RG
TOTOLINK A3000RU
TOTOLINK A3100R
All of the following
TOTOLINK A830r Firmware=4.1.2cu.5182_b20201102
TOTOLINK A830R
All of the following
TOTOLINK A950rg Firmware=4.1.2cu.5161_b20200903
TOTOLINK A950RG
All of the following
TOTOLINK A3000ru Firmware=5.9c.5185_b20201128
TOTOLINK A3000RU
All of the following
TOTOLINK A3100r Firmware=4.1.2cu.5247_b20211129
TOTOLINK A3100R
Event History
Apr 23, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-28028?
CVE-2025-28028 is classified as a high-severity buffer overflow vulnerability.
2
How do I fix CVE-2025-28028?
To mitigate CVE-2025-28028, update affected TOTOLINK devices to the latest firmware version provided by the manufacturer.
3
Which devices are affected by CVE-2025-28028?
CVE-2025-28028 affects TOTOLINK A830R, A950RG, A3000RU, and A3100R routers.
4
What type of vulnerability is CVE-2025-28028?
CVE-2025-28028 is a buffer overflow vulnerability that can be exploited via the downloadFile.cgi process.
5
What impact does CVE-2025-28028 have on affected devices?
CVE-2025-28028 can allow attackers to execute arbitrary code on affected devices, potentially leading to unauthorized access.