CVE-2025-28032: Buffer Overflow
TOTOLINK A800R V4.1.2cu.5137B20200730, A810R V4.1.2cu.5182B20201026, A830R V4.1.2cu.5182B20201102, A950RG V4.1.2cu.5161B20200903, A3000RU V5.9c.5185B20201128, and A3100R V4.1.2cu.5247B20211129 contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through the IpForm parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-28032?
CVE-2025-28032 is rated as a high severity vulnerability due to the potential for remote code execution through a pre-authentication buffer overflow.
How do I fix CVE-2025-28032?
To fix CVE-2025-28032, update the affected TOTOLINK products to the latest firmware version provided by the vendor.
What devices are impacted by CVE-2025-28032?
CVE-2025-28032 affects TOTOLINK A800R, A810R, A830R, A950RG, A3000RU, and A3100R models.
What is the nature of the vulnerability in CVE-2025-28032?
The vulnerability in CVE-2025-28032 is a pre-authentication buffer overflow that can be exploited via the setNoticeCfg function.
Can CVE-2025-28032 be exploited remotely?
Yes, CVE-2025-28032 can potentially be exploited remotely without authentication, allowing attackers to execute arbitrary code.