CVE-2025-28137: OS Command Injection
Published Apr 15, 2025
·Updated
The TOTOLINK A810R V4.1.2cu.5182B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
Affected Software
3 affected components
TOTOLINK A810R
All of the following
TOTOLINK A810r Firmware=4.1.2cu.5182_b20201026
TOTOLINK A810R
Event History
Apr 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-28137?
CVE-2025-28137 is rated as a high severity vulnerability due to its potential for pre-authentication remote command execution.
2
How does CVE-2025-28137 affect the security of the TOTOLINK A810R?
CVE-2025-28137 allows attackers to execute arbitrary commands on the TOTOLINK A810R device without user authentication.
3
How do I fix CVE-2025-28137?
To mitigate CVE-2025-28137, update the TOTOLINK A810R to the latest firmware version that addresses this vulnerability.
4
Who is affected by CVE-2025-28137?
CVE-2025-28137 affects users of the TOTOLINK A810R model running version V4.1.2cu.5182_B20201026.
5
What is the exploit vector for CVE-2025-28137?
The exploit vector for CVE-2025-28137 involves manipulating the NoticeUrl parameter in the setNoticeCfg function.