CVE-2025-28037: OS Command Injection
Published Apr 22, 2025
·Updated
TOTOLINK A810R V4.1.2cu.5182B20201026 and A950RG V4.1.2cu.5161B20200903 were found to contain a pre-auth remote command execution vulnerability in the setDiagnosisCfg function through the ipDomain parameter.
Affected Software
6 affected components
TOTOLINK A810R
TOTOLINK A950RG
All of the following
TOTOLINK A810r Firmware=4.1.2cu.5182_b20201026
TOTOLINK A810R
All of the following
TOTOLINK A950rg Firmware=4.1.2cu.5182_b20201026
TOTOLINK A950RG
Event History
Apr 22, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-28037?
CVE-2025-28037 is classified as a critical pre-auth remote command execution vulnerability.
2
How do I fix CVE-2025-28037?
To mitigate CVE-2025-28037, update your TOTOLINK A810R or A950RG router to the latest firmware version.
3
What are the affected devices mentioned in CVE-2025-28037?
CVE-2025-28037 affects TOTOLINK A810R with firmware V4.1.2cu.5182_B20201026 and A950RG with firmware V4.1.2cu.5161_B20200903.
4
What type of vulnerability is CVE-2025-28037?
CVE-2025-28037 is a remote command execution vulnerability that can be exploited pre-authentication.
5
Can CVE-2025-28037 be exploited remotely?
Yes, CVE-2025-28037 allows for remote exploitation without prior authentication.