CVE-2025-28033: Buffer Overflow
TOTOLINK A800R V4.1.2cu.5137B20200730, A810R V4.1.2cu.5182B20201026, A830R V4.1.2cu.5182B20201102, A950RG V4.1.2cu.5161B20200903, A3000RU V5.9c.5185B20201128, and A3100R V4.1.2cu.5247B20211129 were found to contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through the IpTo parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-28033?
CVE-2025-28033 has been classified as a high severity vulnerability due to its pre-authentication buffer overflow nature.
How do I fix CVE-2025-28033?
Fixing CVE-2025-28033 involves updating your firmware to the latest version released by TOTOLINK that addresses this vulnerability.
What devices are affected by CVE-2025-28033?
CVE-2025-28033 affects several TOTOLINK devices including A800R, A810R, A830R, A950RG, A3000RU, and A3100R.
What is the impact of CVE-2025-28033?
The impact of CVE-2025-28033 includes potential remote code execution and unauthorized access due to the buffer overflow.
Is there a workaround for CVE-2025-28033?
The best temporary workaround for CVE-2025-28033 is to disable any remote management features until the firmware is updated.