First published: Tue Apr 22 2025(Updated: )
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through the IpTo parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A800R firmware | ||
TOTOLINK A810R | ||
TOTOLINK A830R | ||
Totolink A950RG firmware | ||
Totolink A3000RU firmware | ||
Totolink A3100R Firmware | ||
All of | ||
TOTOLink A800R | =4.1.2cu.5137_b20200730 | |
Totolink A800R firmware | ||
All of | ||
Totolink A3600r Firmware | =4.1.2cu.5182_b20201026 | |
TOTOLINK A810R | ||
All of | ||
Totolink A3300r Firmware | =4.1.2cu.5182_b20201102 | |
TOTOLINK A830R | ||
All of | ||
Totolink A950RG firmware | =4.1.2cu.5161_b20200903 | |
Totolink A950RG firmware | ||
All of | ||
Totolink A3000RU Firmware | =5.9c.5185_b20201128 | |
Totolink A3000RU firmware | ||
All of | ||
Totolink A3100R | =4.1.2cu.5247_b20211129 | |
Totolink A3100R Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-28033 has been classified as a high severity vulnerability due to its pre-authentication buffer overflow nature.
Fixing CVE-2025-28033 involves updating your firmware to the latest version released by TOTOLINK that addresses this vulnerability.
CVE-2025-28033 affects several TOTOLINK devices including A800R, A810R, A830R, A950RG, A3000RU, and A3100R.
The impact of CVE-2025-28033 includes potential remote code execution and unauthorized access due to the buffer overflow.
The best temporary workaround for CVE-2025-28033 is to disable any remote management features until the firmware is updated.