PT-2025-13265 · Totolink · Totolink A800R

Published

2025-03-27

·

Updated

2025-03-29

·

CVE-2025-28138

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK A800R version 4.1.2cu.5137 B20200730
Description The issue concerns a remote command execution flaw. Unauthenticated attackers can run arbitrary commands. There have been spotted exploits. It is recommended to monitor logs.
Recommendations For version 4.1.2cu.5137 B20200730, disable remote management as a temporary workaround to minimize the risk of exploitation. Restrict access to the NoticeUrl parameter in the setNoticeCfg function to prevent unauthorized command execution. Monitor logs for suspicious activity.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-28138

Affected Products

Totolink A800R