First published: Tue Apr 15 2025(Updated: )
The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TOTOLINK A810R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-28137 is rated as a high severity vulnerability due to its potential for pre-authentication remote command execution.
CVE-2025-28137 allows attackers to execute arbitrary commands on the TOTOLINK A810R device without user authentication.
To mitigate CVE-2025-28137, update the TOTOLINK A810R to the latest firmware version that addresses this vulnerability.
CVE-2025-28137 affects users of the TOTOLINK A810R model running version V4.1.2cu.5182_B20201026.
The exploit vector for CVE-2025-28137 involves manipulating the NoticeUrl parameter in the setNoticeCfg function.