PT-2025-17653 · Totolink · Totolink A810R

Published

2025-04-23

·

Updated

2025-04-28

·

CVE-2025-28021

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TOTOLINK A810R version 4.1.2cu.5182 B20201026
Description A buffer overflow issue was discovered in the downloadFile.cgi, specifically through the v14 and v3 parameters.
Recommendations For TOTOLINK A810R version 4.1.2cu.5182 B20201026, as a temporary workaround, consider restricting access to the downloadFile.cgi endpoint until a patch is available. Avoid using the v14 and v3 parameters in the affected endpoint until the issue is resolved.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-10009
CVE-2025-28021

Affected Products

Totolink A810R