CVE-2025-28138: OS Command Injection
Published Mar 27, 2025
·Updated
The TOTOLINK A800R V4.1.2cu.5137B20200730 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
Affected Software
3 affected components
TOTOLINK A800R
All of the following
TOTOLINK A800r Firmware=4.1.2cu.5137_b20200730
TOTOLINK A800R
Event History
Mar 27, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2025-28138?
CVE-2025-28138 has a high severity due to its potential for remote command execution.
2
How does CVE-2025-28138 work?
CVE-2025-28138 exploits the setNoticeCfg function through the NoticeUrl parameter to execute arbitrary commands remotely.
3
What devices are affected by CVE-2025-28138?
CVE-2025-28138 specifically affects the TOTOLINK A800R running firmware version V4.1.2cu.5137_B20200730.
4
How do I fix CVE-2025-28138?
To mitigate CVE-2025-28138, upgrade the firmware of your TOTOLINK A800R to the latest version provided by the vendor.
5
What should I do if my device is compromised due to CVE-2025-28138?
If compromised, immediately disconnect the device from the network and perform a factory reset or reflash the firmware.