CVE-2025-28036: OS Command Injection
TOTOLINK A950RG V4.1.2cu.5161B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-28036?
CVE-2025-28036 is considered a critical vulnerability due to its pre-auth remote command execution capabilities.
How do I fix CVE-2025-28036?
To mitigate CVE-2025-28036, update the TOTOLINK A950RG firmware to the latest version provided by the vendor.
What impact does CVE-2025-28036 have on my device?
CVE-2025-28036 allows an attacker to execute arbitrary commands on the device without authentication, potentially compromising the system.
Is CVE-2025-28036 exploit remote or local?
CVE-2025-28036 is a remote vulnerability, allowing exploitation from outside the network without any local access.
Which devices are affected by CVE-2025-28036?
CVE-2025-28036 specifically affects the TOTOLINK A950RG model running the specified vulnerable firmware version.