PT-2025-17571 · Totolink · Totolink Ex1200T

Published

2025-04-12

·

Updated

2025-04-29

·

CVE-2025-28038

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK EX1200T version 4.1.2cu.5232 B20210713
Description The issue is a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter. This allows for remote command execution without prior authentication.
Recommendations For TOTOLINK EX1200T version 4.1.2cu.5232 B20210713, consider disabling the setWebWlanIdx function until a patch is available to prevent exploitation through the webWlanIdx parameter. Restrict access to the vulnerable function to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-05175
CVE-2025-28038

Affected Products

Totolink Ex1200T