PT-2025-17555 · Totolink · Totolink A810R+1

Published

2025-04-22

·

Updated

2025-04-29

·

CVE-2025-28037

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK A810R version 4.1.2cu.5182 B20201026 TOTOLINK A950RG version 4.1.2cu.5161 B20200903
Description The issue is a pre-auth remote command execution vulnerability. It is located in the setDiagnosisCfg function and can be exploited through the ipDomain parameter.
Recommendations For TOTOLINK A810R version 4.1.2cu.5182 B20201026, consider disabling the setDiagnosisCfg function until a patch is available. For TOTOLINK A950RG version 4.1.2cu.5161 B20200903, restrict access to the ipDomain parameter in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-10704
CVE-2025-28037

Affected Products

Totolink A810R
Totolink A950Rg