PT-2025-16340 · Totolink · Totolink A810R

Published

2025-04-15

·

Updated

2025-05-12

·

CVE-2025-28137

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK A810R version 4.1.2cu.5182 B20201026
Description The issue concerns a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter. This allows for unauthorized execution of commands.
Recommendations For version 4.1.2cu.5182 B20201026, consider disabling the setNoticeCfg function until a patch is available. Restrict access to the NoticeUrl parameter to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-05804
CVE-2025-28137

Affected Products

Totolink A810R