PT-2025-17554 · Totolink · Totolink A810R

Published

2025-04-22

·

Updated

2025-04-22

·

CVE-2025-28031

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions TOTOLINK A810R version 4.1.2cu.5182 B20201026
Description The issue concerns a hardcoded password for the telnet service, which is stored in the product.ini file.
Recommendations For version 4.1.2cu.5182 B20201026, consider changing the hardcoded password for the telnet service in the product.ini file to a unique and secure password. As a temporary workaround, consider disabling the telnet service until a patch is available. Restrict access to the product.ini file to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-04920
CVE-2025-28031

Affected Products

Totolink A810R