First published: Tue Apr 22 2025(Updated: )
TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote command execution vulnerability in the setDiagnosisCfg function through the ipDomain parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TOTOLINK A810R | ||
TOTOlink A950RG | ||
All of | ||
Totolink A3600r Firmware | =4.1.2cu.5182_b20201026 | |
TOTOLINK A810R | ||
All of | ||
TOTOlink A950RG | =4.1.2cu.5182_b20201026 | |
TOTOlink A950RG |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-28037 is classified as a critical pre-auth remote command execution vulnerability.
To mitigate CVE-2025-28037, update your TOTOLINK A810R or A950RG router to the latest firmware version.
CVE-2025-28037 affects TOTOLINK A810R with firmware V4.1.2cu.5182_B20201026 and A950RG with firmware V4.1.2cu.5161_B20200903.
CVE-2025-28037 is a remote command execution vulnerability that can be exploited pre-authentication.
Yes, CVE-2025-28037 allows for remote exploitation without prior authentication.