PT-2025-17649 · Totolink · Totolink A800R

Published

2025-04-23

·

Updated

2025-04-28

·

CVE-2025-28020

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TOTOLINK A800R version 4.1.2cu.5137 B20200730
Description A buffer overflow issue was discovered in the downloadFile.cgi endpoint through the v25 parameter. This allows for potential exploitation.
Recommendations For TOTOLINK A800R version 4.1.2cu.5137 B20200730, as a temporary workaround, consider restricting access to the downloadFile.cgi endpoint until a patch is available. Avoid using the v25 parameter in the downloadFile.cgi endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-10008
CVE-2025-28020

Affected Products

Totolink A800R