CVE-2025-28136: Buffer Overflow
Published Apr 15, 2025
·Updated
TOTOLINK A800R V4.1.2cu.5137B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi.
Affected Software
3 affected components
TOTOLINK A800R
All of the following
TOTOLINK A800r Firmware=4.1.2cu.5137_b20200730
TOTOLINK A800R
Event History
Apr 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-28136?
CVE-2025-28136 is classified as a high severity vulnerability due to its potential for remote exploitation through a buffer overflow.
2
How do I fix CVE-2025-28136?
To mitigate CVE-2025-28136, update the firmware of the TOTOLINK A800R router to the latest version provided by the vendor.
3
What devices are affected by CVE-2025-28136?
CVE-2025-28136 specifically affects the TOTOLINK A800R router running firmware version V4.1.2cu.5137_B20200730.
4
What type of vulnerability is CVE-2025-28136?
CVE-2025-28136 is a buffer overflow vulnerability found in the downloadFile.cgi component of the affected router.
5
Can CVE-2025-28136 be exploited remotely?
Yes, CVE-2025-28136 can potentially be exploited remotely, allowing attackers to execute arbitrary code on the affected device.