PT-2025-17650 · Totolink · Totolink A810R

Published

2025-04-23

·

Updated

2025-04-28

·

CVE-2025-28022

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TOTOLINK A810R version 4.1.2cu.5182 B20201026
Description A buffer overflow issue was discovered in the downloadFile.cgi endpoint through the v25 parameter.
Recommendations For TOTOLINK A810R version 4.1.2cu.5182 B20201026, avoid using the v25 parameter in the "downloadFile.cgi" endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the downloadFile.cgi endpoint to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-10010
CVE-2025-28022

Affected Products

Totolink A810R