CVE-2025-28018
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Apr 23, 2025
Updated: May 6, 2025
CWE ID 120
Summary
CVE-2025-28018 is a newly discovered vulnerability affecting the TOTOLINK A800R V4.1.2cu.5137_B20200730 firmware. The issue stems from a buffer overflow vulnerability located in the downloadFile.cgi script, which can be triggered via the v14 parameter. Successful exploitation of this flaw could lead to arbitrary code execution, posing a significant risk to network security. Users are advised to update their firmware as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- TOTOLINK