CVE-2025-28029: Buffer Overflow
Published Apr 22, 2025
·Updated
TOTOLINK A830R V4.1.2cu.5182B20201102, A950RG V4.1.2cu.5161B20200903, A3000RU V5.9c.5185B20201128, and A3100R V4.1.2cu.5247B20211129 were found to contain a buffer overflow vulnerability in cstecgi.cgi
Affected Software
12 affected components
TOTOLINK A830R
TOTOLINK A950RG
TOTOLINK A3000RU
TOTOLINK A3100R
All of the following
TOTOLINK A830r Firmware=4.1.2cu.5182_b20201102
TOTOLINK A830R
All of the following
TOTOLINK A950rg Firmware=4.1.2cu.5161_b20200903
TOTOLINK A950RG
All of the following
TOTOLINK A3000ru Firmware=5.9c.5185_b20201128
TOTOLINK A3000RU
All of the following
TOTOLINK A3100r Firmware=4.1.2cu.5247_b20211129
TOTOLINK A3100R
Event History
Apr 22, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-28029?
CVE-2025-28029 has a severity rating that indicates it could allow remote code execution due to a buffer overflow.
2
How do I fix CVE-2025-28029?
To fix CVE-2025-28029, users should update their affected TOTOLINK router firmware to the latest version provided by the vendor.
3
What devices are affected by CVE-2025-28029?
CVE-2025-28029 affects TOTOLINK A830R, A950RG, A3000RU, and A3100R router models.
4
What type of vulnerability is CVE-2025-28029?
CVE-2025-28029 is classified as a buffer overflow vulnerability in the cstecgi.cgi component.
5
Can CVE-2025-28029 be exploited remotely?
Yes, CVE-2025-28029 can be exploited remotely, allowing attackers to execute arbitrary code.