CVE-2025-28035: OS Command Injection
Published Apr 22, 2025
·Updated
TOTOLINK A830R V4.1.2cu.5182B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
Affected Software
13 affected components
TOTOLINK A830R
All of the following
TOTOLINK A830r Firmware=4.1.2cu.5182_b20201102
TOTOLINK A830R
All of the following
TOTOLINK A3100r Firmware=4.1.2cu.5247_b20211129
TOTOLINK A3100R
All of the following
TOTOLINK A810r Firmware=4.1.2cu.5182_b20201026
TOTOLINK A810R
All of the following
TOTOLINK A800r Firmware=4.1.2cu.5137_b20200730
TOTOLINK A800R
All of the following
TOTOLINK A3000ru Firmware=5.9c.5185_b20201128
TOTOLINK A3000RU
All of the following
TOTOLINK A950rg Firmware=4.1.2cu.5161_b20200903
TOTOLINK A950RG
Event History
Apr 22, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-28035?
CVE-2025-28035 is considered a high-severity vulnerability due to its potential for pre-auth remote command execution.
2
How do I fix CVE-2025-28035?
To mitigate CVE-2025-28035, update the TOTOLINK A830R to the latest firmware version provided by the vendor.
3
What type of vulnerability is CVE-2025-28035?
CVE-2025-28035 is a pre-authentication remote command execution vulnerability.
4
Could CVE-2025-28035 affect my network security?
Yes, CVE-2025-28035 could significantly compromise your network security by allowing an attacker to execute commands remotely.
5
Is CVE-2025-28035 publicly known?
Yes, CVE-2025-28035 has been publicly disclosed, making it crucial to address the vulnerability.