PT-2025-17648 · Totolink · Totolink A800R

Published

2025-04-23

·

Updated

2025-05-06

·

CVE-2025-28019

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TOTOLINK A800R version 4.1.2cu.5137 B20200730
Description A buffer overflow vulnerability was found in the downloadFile.cgi component. This issue affects the TOTOLINK A800R router.
Recommendations For version 4.1.2cu.5137 B20200730, as a temporary workaround, consider disabling the downloadFile.cgi component until a patch is available. Restrict access to the downloadFile.cgi component to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-10007
CVE-2025-28019

Affected Products

Totolink A800R